Malicious PDF — malware analysis report

Static analysis result for SHA-256 31f1d6c96831cbce…

MALICIOUS

PDF

50.9 KB Created: 2020-08-31 03:29:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 05d7bd398cd6ff8cb82d2a2e40120a7b SHA-1: 0a160e0f4e19e8102ffb4d4d88231228e6ac2fe9 SHA-256: 31f1d6c96831cbce36d41cec134a2f51e52fc766d29f44c600f2c5ba79d4bfd0
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF was flagged for containing a large number of external links, with one pointing to a known malicious redirector. The document body contains obfuscated text and URLs, including a link to 'ttraff.com', which is identified as a malicious redirector. The presence of numerous Shopify links suggests an attempt to leverage legitimate platforms for hosting or distributing malicious content, potentially for SEO abuse or to mask malicious activity. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=dolores+cannon+three+waves+of+volunt
    • https://cdn.shopify.com/s/files/1/0433/8394/7427/files/punerupebilo.pdf
    • https://cdn.shopify.com/s/files/1/0430/9961/9492/files/rezunuf.pdf
    • https://cdn.shopify.com/s/files/1/0436/9891/3435/files/dlink_dir_628_specs.pdf
    • https://cdn.shopify.com/s/files/1/0429/6425/4883/files/edgar_allan_poe_the_black_cat.pdf
    • https://cdn.shopify.com/s/files/1/0429/9957/8773/files/sejatuj.pdf
    • https://cdn.shopify.com/s/files/1/0431/8471/7979/files/25671980619.pdf
    • https://cdn.shopify.com/s/files/1/0466/3905/5013/files/55228023812.pdf
    • https://cdn.shopify.com/s/files/1/0435/8491/3563/files/53043378029.pdf
    • https://cdn.shopify.com/s/files/1/0435/4624/7332/files/gosupirok.pdf
    • https://cdn.shopify.com/s/files/1/0435/4179/0871/files/go_go_govinda_video_song_free_downlo.pdf
    • https://cdn.shopify.com/s/files/1/0438/4381/3538/files/2011_chevy_equinox_car_manual.pdf
    • https://cdn.shopify.com/s/files/1/0437/2656/9633/files/double_displacement_reaction_definition.pdf
    • https://cdn.shopify.com/s/files/1/0462/0894/2233/files/poe_vortex_guide.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000089f6.bin
cbd9d2a8122c282ad075f88672264d85309f4751e1e42d0c4c046e87d511265e
pdf-font-stream PDF embedded font (sfnt) at offset 0x89F6 5120 bytes
font_01_sfnt_off00009b6a.bin
e90369b6d5d1ebb92c1f61acb74f991a1ee096afeea6418f3097973c44fe7e1e
pdf-font-stream PDF embedded font (sfnt) at offset 0x9B6A 10368 bytes