Malicious PDF — malware analysis report

Static analysis result for SHA-256 402f61ec8bbe6e06…

MALICIOUS

PDF

40.6 KB Created: 2020-08-29 23:02:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2bc6a20e8c31aa2fa41c1b4e129643b5 SHA-1: bbc5df7ef8d6be4bf5cb82a594b18096b485934c SHA-256: 402f61ec8bbe6e06b00bf5814e29eb6f77c897b11eed3a47326ab81c0dc98ad5
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

This PDF file contains a large number of embedded links, many of which point to a redirector service. The primary malicious URL identified is ttraff.com, which is known to host malicious content. The document body, though heavily obfuscated, contains references to Motorola pagers and appears to be a lure to drive traffic to the malicious link. No scripts were extracted, but the PDF structure and embedded links strongly suggest a phishing or redirection attack.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=motorola+p25+pager
    • https://cdn.shopify.com/s/files/1/0435/0659/8040/files/microsoft_office_creating_labels_from_excel_spreadsheet.pdf
    • https://cdn.shopify.com/s/files/1/0431/6617/1296/files/78561003458.pdf
    • https://cdn.shopify.com/s/files/1/0435/3458/1911/files/52698941568.pdf
    • https://cdn.shopify.com/s/files/1/0430/6350/9143/files/tolilopaxofini.pdf
    • https://cdn.shopify.com/s/files/1/0437/4275/7013/files/28977026365.pdf
    • https://static.usrfiles.com/ugd/b8c837_0abbcbbff42644c4a10cc8ae1872525a.pdf
    • https://static.usrfiles.com/ugd/b8c837_e91ff4138f344b0bbd5ffb5a6cf491fe.pdf
    • https://static.usrfiles.com/ugd/b8c837_04ba36cb25b14989b3ddd3fe3d2cb6fb.pdf
    • https://static.usrfiles.com/ugd/b8c837_da0e981594ba4776892747714e25d664.pdf
    • https://static.usrfiles.com/ugd/b8c837_c802f908fff94ecfb8e5cb5236a1af91.pdf
    • https://static.usrfiles.com/ugd/e2c6c1_4126399a73d5460a98bfd61c72c3573f.pdf
    • https://static.usrfiles.com/ugd/6846fe_16830775fe384478aaf7a8ba587b253b.pdf
    • https://static.usrfiles.com/ugd/b8c837_07ea9e21372841c4a0eb190b456ddc9a.pdf
    • https://cdn.shopify.com/s/files/1/0434/4076/7132/files/height_weight_bmi_chart.pdf
    • https://cdn.shopify.com/s/files/1/0427/6404/2396/files/10516899614.pdf
    • https://cdn.shopify.com/s/files/1/0431/0971/2033/files/how_to_mirror_an_object_in_maya.pdf
    • https://cdn.shopify.com/s/files/1/0435/3572/8794/files/arsenal_vs_fiorentina_highlights.pdf
    • https://cdn.shopify.com/s/files/1/0462/7690/3061/files/ranotagewututixokokebaf.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000061fa.bin
74eb7259c61794923301b1c93558e098682853a7e71a4bcaa2c82651aca69931
pdf-font-stream PDF embedded font (sfnt) at offset 0x61FA 5068 bytes
font_01_sfnt_off00007354.bin
29821a152699e4b1a296b49a660ba1e858d1abd32bd438fb4c896e4030c6f71c
pdf-font-stream PDF embedded font (sfnt) at offset 0x7354 10068 bytes