Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b3f27282a939ecd…

MALICIOUS

PDF

38.2 KB Created: 2020-08-30 08:49:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b340a8510a0a48b92244cfa925cf7ce7 SHA-1: 2f0fbf8011e17d7cc8c4ae62fef6aab883490478 SHA-256: 4b3f27282a939ecd976fed4e1be0ee2e403a17991ef83ac54c3c7239a812a2e2
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, directing users to 'ttraff.cc'. This indicates an attempt to lead the user to a malicious site. The PDF also contains a link farm, suggesting a SEO poisoning or spamming tactic. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the exact lure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=livro+o+neoliberalismo+hist%25C3%25B3ria+e+implica%25C3%25A7%25C3%25B5es+pdf
    • https://cdn.shopify.com/s/files/1/0428/8996/9820/files/ibps_rrb_admit_card_download_2020.pdf
    • https://cdn.shopify.com/s/files/1/0432/7034/0772/files/apqp4wind_manual.pdf
    • https://cdn.shopify.com/s/files/1/0431/9461/3924/files/basic_life_support_american_heart_association.pdf
    • https://cdn.shopify.com/s/files/1/0434/4587/8941/files/belafom.pdf
    • https://static.usrfiles.com/ugd/b8c837_3c00d0d0797c4653b174009bcae3e607.pdf
    • https://static.usrfiles.com/ugd/b8c837_1799b72328164383a0be2068d69752dc.pdf
    • https://static.usrfiles.com/ugd/89363e_9878e064f87f44f29d29988edafe5c00.pdf
    • https://static.usrfiles.com/ugd/11f207_08fb5df8f70b46d281adfd550d5764fe.pdf
    • https://static.usrfiles.com/ugd/b8c837_39b8b4365f7e4d7295fc93e10f219f40.pdf
    • https://cdn.shopify.com/s/files/1/0430/4083/3690/files/23939803335.pdf
    • https://cdn.shopify.com/s/files/1/0439/6630/0318/files/42944182594.pdf
    • https://cdn.shopify.com/s/files/1/0437/5930/4865/files/george_foreman_indoor_outdoor_grill_recipes.pdf
    • https://cdn.shopify.com/s/files/1/0430/9028/0609/files/69526952220.pdf
    • https://cdn.shopify.com/s/files/1/0461/9013/3406/files/nowolosefudifawatul.pdf
    • https://cdn.shopify.com/s/files/1/0429/2070/6204/files/99059977705.pdf
    • https://cdn.shopify.com/s/files/1/0429/2119/7724/files/serotonin_syndrome_treatment.pdf
    • https://cdn.shopify.com/s/files/1/0431/6286/1730/files/69110933237.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000505d.bin
27aece11b4321eaf69eaac69eced3204313584ae173450fe771da95245efc4d9
pdf-font-stream PDF embedded font (sfnt) at offset 0x505D 6072 bytes
font_01_sfnt_off000063fc.bin
c4f4bfab58a74ed64cb907d21b8d05b344b9df58d6fcd5275aef1688a25feb1d
pdf-font-stream PDF embedded font (sfnt) at offset 0x63FC 12424 bytes