Malicious PDF — malware analysis report

Static analysis result for SHA-256 391dbf23debc7011…

MALICIOUS

PDF

41.7 KB Created: 2020-08-21 06:03:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b5399e898246d51285c0ebb3717a7ef5 SHA-1: 0744893ecb13ac6ec4142ea96d002627d56484ef SHA-256: 391dbf23debc70115dc29223d8118ae761d61dfb4b998f6a498d93ce2a49b672
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link to a known malicious redirector, ttraff.com, disguised as a crossword answer key. It also hosts a large number of other PDF files, likely for SEO poisoning to improve search engine ranking and lure unsuspecting users. The ML classifier strongly indicates maliciousness. No scripts were extracted, but the primary attack vector is the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=mesoamerican+world+crossword+answer+key
    • http://vakawugox.1984hair.com/uploads/1/3/1/0/131071278/afb6bc0bb567efe.pdf
    • http://kadodevi.adelantechc.org/uploads/1/3/2/6/132682878/siwiruba-lebuduj-bunibuzowiwo-vofuxa.pdf
    • https://cdn.shopify.com/s/files/1/0437/3151/7592/files/brush_lettering_practice.pdf
    • https://cdn.shopify.com/s/files/1/0437/8673/1671/files/14979118673.pdf
    • https://cdn.shopify.com/s/files/1/0437/3685/8776/files/joliriwasejimaxov.pdf
    • https://cdn.shopify.com/s/files/1/0432/9046/0324/files/fahrenheit_451_study_guide_answers.pdf
    • https://cdn.shopify.com/s/files/1/0429/5757/0207/files/directv2pc_media_server.pdf
    • https://cdn.shopify.com/s/files/1/0427/5650/5756/files/vujozabuxonexosune.pdf
    • https://cdn.shopify.com/s/files/1/0432/7365/0334/files/sling_psychrometer.pdf
    • https://cdn.shopify.com/s/files/1/0428/3963/8179/files/2558647817.pdf
    • https://cdn.shopify.com/s/files/1/0431/9562/9725/files/82637864457.pdf
    • https://cdn.shopify.com/s/files/1/0434/4184/8470/files/proceso_de_aprendizaje_psicologia.pdf
    • https://cdn.shopify.com/s/files/1/0430/8094/1729/files/baxose.pdf
    • https://cdn.shopify.com/s/files/1/0435/5407/8871/files/masafadewa.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000064f4.bin
3d6eb6837b0fb0fa60318df0694ee206717cf241896170ce638d9e1440610d78
pdf-font-stream PDF embedded font (sfnt) at offset 0x64F4 5348 bytes
font_01_sfnt_off0000772b.bin
a080268a949e83bb4201672adf2ee679846d6a0dcea0124038a3f9eb9055db75
pdf-font-stream PDF embedded font (sfnt) at offset 0x772B 10160 bytes