Malicious PDF — malware analysis report

Static analysis result for SHA-256 47f9fbc8fbfd9643…

MALICIOUS

PDF

41.1 KB Created: 2020-10-17 02:23:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 26b0a5cb71538564587d9503b606cb81 SHA-1: f15bc4c88c0f261cf6e1295ad7a5448cd1f3ed31 SHA-256: 47f9fbc8fbfd9643381c7b498a4c37ac8256d63fc24d2c89f7c1d502563f8cfc
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was identified as malicious due to a critical heuristic firing for a malicious redirector link. This link, 'https://ttraff.me/123?keyword=farberware+turbo+convection+oven+manual', is likely intended to lead users to a malicious site. Additionally, the PDF contains a large number of embedded links, many pointing to Shopify domains, which is characteristic of a link farm used to artificially inflate search engine rankings or distribute malicious content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/123?keyword=farberware+turbo+convection+oven+manual
    • https://cdn.shopify.com/s/files/1/0483/8431/1447/files/the_immortals_of_meluha_malayalam_full_book_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0433/6146/8574/files/kayaks_los_angeles.pdf
    • https://cdn.shopify.com/s/files/1/0476/7481/8726/files/raxupubaret.pdf
    • https://cdn.shopify.com/s/files/1/0482/9777/1176/files/freddy_files.pdf
    • https://cdn.shopify.com/s/files/1/0266/8665/2614/files/60361197450.pdf
    • https://cdn.shopify.com/s/files/1/0484/3051/4330/files/la_fitness_flagler_miami.pdf
    • https://cdn.shopify.com/s/files/1/0497/4968/8483/files/jurnal_pediculus_humanus_corporis.pdf
    • https://cdn.shopify.com/s/files/1/0499/5088/4008/files/rilunamoga.pdf
    • https://cdn.shopify.com/s/files/1/0434/8274/2950/files/berceau_des_sens_guide_michelin.pdf
    • https://cdn.shopify.com/s/files/1/0480/9742/7619/files/lord_of_ultima.pdf
    • https://cdn.shopify.com/s/files/1/0268/8571/8189/files/6_feet_apart_drive_mp3.pdf
    • https://cdn.shopify.com/s/files/1/0499/8837/0582/files/50213711879.pdf
    • https://cdn.shopify.com/s/files/1/0266/8494/8653/files/tikesasekamexapupolesavu.pdf
    • https://cdn.shopify.com/s/files/1/0496/6491/7661/files/kexefifiwimaxipa.pdf
    • https://cdn.shopify.com/s/files/1/0431/7125/0333/files/satan_persona_5_build.pdf
    • https://cdn.shopify.com/s/files/1/0497/4247/9521/files/myupsi_portal_3_login.pdf
    • https://uploads.strikinglycdn.com/files/fe070516-92a9-4a75-abb9-43182591bfe7/jovagufevuzakuvikagorokop.pdf
    • https://uploads.strikinglycdn.com/files/e1bc18bb-223b-4b8a-bf09-06ba5db2ff79/peduz.pdf
    • https://uploads.strikinglycdn.com/files/dd16777f-4ac1-4924-bd55-ecf84d06a078/88998663921.pdf
    • https://cdn.shopify.com/s/files/1/0466/5281/7573/files/last_battleground_mech_apk_download.pdf
    • https://cdn.shopify.com/s/files/1/0486/4068/8296/files/samsung_rugby_4_specs.pdf
    • https://cdn.shopify.com/s/files/1/0501/8697/7441/files/mapa_turistico_lisboa_2020.pdf
    • https://cdn.shopify.com/s/files/1/0435/2219/5607/files/23765435564.pdf
    • https://cdn.shopify.com/s/files/1/0432/0899/9072/files/wapiliwe.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000062a6.bin
6dfffb5bcfa762176c168bf02af5970303482f8f17a55b0e21d21d754681e8e9
pdf-font-stream PDF embedded font (sfnt) at offset 0x62A6 5016 bytes
font_01_sfnt_off000073b9.bin
f6cf458edc0d751c03292c121ed9c9581bec2bed81eb66bb836a8538f4dd3e6e
pdf-font-stream PDF embedded font (sfnt) at offset 0x73B9 10388 bytes