Malicious PDF — malware analysis report

Static analysis result for SHA-256 41254cb576175bdc…

MALICIOUS

PDF

43.4 KB Created: 2020-08-19 16:20:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0f9af1316754f7c16793607d008ce039 SHA-1: 15b2d1c992f85011060fa0acf9634ba4035acd97 SHA-256: 41254cb576175bdc6bcd0169a0f2d5b51c44659931d4b1b5c4d40a0ae8c43f32
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. The document body, though heavily obfuscated, contains the same URL, suggesting it's the primary lure. The PDF also exhibits characteristics of a link farm, with numerous external links, many hosted on Shopify, likely for SEO manipulation to increase visibility of the malicious content. The ML classifier strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=anuraga+devatha+songs+free++doregama
    • http://files.thepalmettolog.com/uploads/1/3/1/6/131606281/231da.pdf
    • http://files.eutropiatours.com/uploads/1/3/2/7/132741334/bapejuruxopugaj-kavitu.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/wanojexabe.pdf
    • https://cdn.shopify.com/s/files/1/0431/5503/0170/files/the_bourne_supremacy_book_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0435/3766/2103/files/adnexitis_adalah.pdf
    • https://cdn.shopify.com/s/files/1/0432/6850/5766/files/48220944536.pdf
    • https://cdn.shopify.com/s/files/1/0438/6160/6550/files/anestesia_local_en_odontologia_carlos_macouzet_olivar_gratis.pdf
    • https://cdn.shopify.com/s/files/1/0440/0896/4246/files/3753468101.pdf
    • https://cdn.shopify.com/s/files/1/0434/0183/8757/files/14852315060.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006838.bin
324cf60a25d97fba403162befa569c50d40eeef0965e397896103f201e2653a2
pdf-font-stream PDF embedded font (sfnt) at offset 0x6838 5336 bytes
font_01_sfnt_off00007a34.bin
2c90d9ce30144e061ff3561c095b41254584d902e9da89a79e5d7010bc4ed707
pdf-font-stream PDF embedded font (sfnt) at offset 0x7A34 12100 bytes