Malicious PDF — malware analysis report

Static analysis result for SHA-256 4938637fa3efa630…

MALICIOUS

PDF

42.3 KB Created: 2020-09-01 17:30:28 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: af7a526fe01c6c10027e62e6768b12ce SHA-1: a84d4e1a2f2c1f898f821bf9bd8d7ad9ef5fb514 SHA-256: 4938637fa3efa6306754cd54456311192b183500741b29e3effb51a4c4df2773
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link to a known malicious redirector, ttraff.com, disguised as a patient handout. This indicates a phishing attempt to redirect users to malicious content. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=achilles+tendonitis+patient+handout+pdf
    • https://cdn.shopify.com/s/files/1/0449/9308/5598/files/carol_kaye_books.pdf
    • https://cdn.shopify.com/s/files/1/0435/8632/2600/files/lutaforofom.pdf
    • https://cdn.shopify.com/s/files/1/0431/4326/6458/files/59245213023.pdf
    • https://cdn.shopify.com/s/files/1/0437/7755/6629/files/um_dia_livro.pdf
    • https://cdn.shopify.com/s/files/1/0461/7096/4131/files/abcya_animate_android.pdf
    • https://cdn.shopify.com/s/files/1/0449/6467/5752/files/xray_1._12._2_texture_pack.pdf
    • https://cdn.shopify.com/s/files/1/0432/1837/0728/files/70733994448.pdf
    • https://cdn.shopify.com/s/files/1/0430/3834/3322/files/bed_sheets_set_online.pdf
    • https://static.usrfiles.com/ugd/d94ae5_f0175e24950a40eaa3087892011ca321.pdf
    • https://static.usrfiles.com/ugd/9757e7_83b612d7f3c24820ac1ec0c445ebe143.pdf
    • https://static.usrfiles.com/ugd/b8c837_3f859ae14ad842668a2045c447be4da2.pdf
    • https://cdn.shopify.com/s/files/1/0428/8688/9625/files/bixatev.pdf
    • https://cdn.shopify.com/s/files/1/0464/7911/4408/files/26455198347.pdf
    • https://cdn.shopify.com/s/files/1/0435/1708/3802/files/jitudosixokevul.pdf
    • https://cdn.shopify.com/s/files/1/0431/9707/1524/files/rachel_ramras_nude.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://static.usrfiles.com/ugd/d

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000677f.bin
c1146766a8a4e09e030547ba6a6cea79ad44f3431ee8ad6901490936e856d032
pdf-font-stream PDF embedded font (sfnt) at offset 0x677F 5136 bytes
font_01_sfnt_off000078ff.bin
b7ceee934eb494608228e7b09c78ca3779b32f663d5f24fedefc4291f131653e
pdf-font-stream PDF embedded font (sfnt) at offset 0x78FF 10332 bytes