Malicious PDF — malware analysis report

Static analysis result for SHA-256 2a55a5c9148b5589…

MALICIOUS

PDF

54.1 KB Created: 2020-08-11 19:52:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: befaf5ecc564d60659ddf20b4a446422 SHA-1: f19ae693322512c6f7094e0fc7d8d8e47197d60b SHA-256: 2a55a5c9148b5589da0acec73c746ac7a99c684d6b774326035fbc26f92468ab
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a mass of external links, including a critical redirector link to ttraff.com, suggesting a phishing or scam lure. The document body, though heavily obfuscated, contains the string "Tumor de pancreas pdf" and the malicious URL, reinforcing the lure. The presence of numerous shopify.com links indicates a link farm used to obscure the ultimate destination.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=tumor+de+pancreas+pdf
    • http://files.designersink.us/uploads/1/3/2/6/132681855/8325908.pdf
    • http://files.mrscooley.com/uploads/1/3/0/7/130775228/d694b865c3839.pdf
    • https://cdn.shopify.com/s/files/1/0432/5828/2152/files/betulia_liberata.pdf
    • https://cdn.shopify.com/s/files/1/0432/1984/5278/files/15088961682.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/zetelonum.pdf
    • https://cdn.shopify.com/s/files/1/0431/5326/0700/files/mier_y_teran_report.pdf
    • http://files.cdlynn.people.ua.edu/uploads/1/3/1/3/131382243/8241403.pdf
    • https://cdn.shopify.com/s/files/1/0432/2390/8520/files/sibagigomal.pdf
    • https://cdn.shopify.com/s/files/1/0435/6207/4261/files/3433537146.pdf
    • https://cdn.shopify.com/s/files/1/0431/5794/6519/files/37815991940.pdf
    • https://cdn.shopify.com/s/files/1/0428/5127/0823/files/xogutopafekelosumilo.pdf
    • https://cdn.shopify.com/s/files/1/0434/9480/1568/files/24952996254.pdf
    • https://cdn.shopify.com/s/files/1/0433/9246/7109/files/6th_grade_fiction_reading_passages.pdf
    • https://cdn.shopify.com/s/files/1/0451/2792/5925/files/etnocentrismo_y_androcentrismo.pdf
    • https://cdn.shopify.com/s/files/1/0430/8631/5682/files/63528017659.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/sopituwoxo.pdf
    • https://cdn.shopify.com/s/files/1/0435/2360/4631/files/lufojixajuge.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000098e8.bin
9ce2eff5d6d3db5aeabfd83e19cc771164bfed919a5ec1fa2f0f93e7d7d4043a
pdf-font-stream PDF embedded font (sfnt) at offset 0x98E8 5220 bytes
font_01_sfnt_off0000aa8e.bin
8acb815f75685409efffac50843f5bbceec51369870ed1515a11bb901936ef71
pdf-font-stream PDF embedded font (sfnt) at offset 0xAA8E 9828 bytes