Malicious PDF — malware analysis report

Static analysis result for SHA-256 3a62f40f7a9a63d6…

MALICIOUS

PDF

66.0 KB Created: 2020-08-15 01:26:28 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 24a6497bbe74a3b1727a97ae8a1a001d SHA-1: c315c8fb65eeaac6392df675ff44695fc12b6c14 SHA-256: 3a62f40f7a9a63d6663347f50ab7fcb5afd4e62116b21970ef5b4b14234617df
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link to a known malicious redirector, ttraff.com, which is disguised as a financial reporting manual. The document also includes a large number of links to other PDFs hosted on Shopify, likely as part of an SEO spam or link farm tactic to improve the redirector's ranking. The ML classifier strongly indicated maliciousness, and the overall structure suggests a phishing or scam attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=australian+financial+reporting+manual+kpmg
    • http://files.lalearningacademy.com/uploads/1/3/1/4/131453598/judababin_wenademivexajes.pdf
    • http://files.rockclimbingprogear.com/uploads/1/3/1/6/131606060/wujodutamofub-xupasubere.pdf
    • http://besidezip.piscasaw.com/uploads/1/3/1/3/131384429/3917684.pdf
    • https://cdn.shopify.com/s/files/1/0434/0904/7708/files/ffxiv_dps_counter.pdf
    • https://cdn.shopify.com/s/files/1/0433/7205/2643/files/convert_to_word_file_using_python.pdf
    • https://cdn.shopify.com/s/files/1/0454/4217/1038/files/mathematics_vision_project.pdf
    • https://cdn.shopify.com/s/files/1/0428/0814/8127/files/79607908418.pdf
    • https://cdn.shopify.com/s/files/1/0434/5564/3813/files/pizufox.pdf
    • https://cdn.shopify.com/s/files/1/0434/3015/0300/files/61609698330.pdf
    • https://cdn.shopify.com/s/files/1/0430/9952/1178/files/mopig.pdf
    • https://cdn.shopify.com/s/files/1/0437/0772/8023/files/origin_of_atmosphere.pdf
    • https://cdn.shopify.com/s/files/1/0434/7618/9346/files/filizajetora.pdf
    • https://cdn.shopify.com/s/files/1/0429/1254/6975/files/77726366655.pdf
    • https://cdn.shopify.com/s/files/1/0433/5131/0488/files/noxakebela.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c387.bin
0176652bfad2c6fb8c5cab0331b82703f4f4d851e4cb65dcf9eadda4a107064f
pdf-font-stream PDF embedded font (sfnt) at offset 0xC387 5388 bytes
font_01_sfnt_off0000d5c4.bin
28d56939ed63ff9c7aeecc2c6406e6154e224b1e7a4e12953346b746d5edd3ac
pdf-font-stream PDF embedded font (sfnt) at offset 0xD5C4 11064 bytes