Malicious PDF — malware analysis report

Static analysis result for SHA-256 55c254b6c4484038…

MALICIOUS

PDF

111.4 KB Created: 2020-08-04 15:12:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b10aacb99a7b0f93bd097446e82caa8c SHA-1: 3f25508cb90312f300c1942a8e75e4a298294fbd SHA-256: 55c254b6c44840380cb444aa78cdde98cb8da042c3f58461901f5b32fd562867
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a heuristic firing for a malicious redirector link pointing to 'ttraff.com'. This URL is presented in the document body, disguised as a textbook PDF. The link farm heuristic indicates the PDF is designed to host numerous external links, likely for SEO poisoning or to distribute further malicious content. The ML classifier strongly indicates maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=ways+of+the+world+textbook+pdf+strayer
    • http://files.audridubois.com/uploads/1/3/0/7/130775490/4459621.pdf
    • http://files.headlandparkartistprecinct.com/uploads/1/3/2/6/132681362/sizivomotutako_wulapesude_rakaxuj.pdf
    • http://files.childprotectionresponsecenter.org/uploads/1/3/1/8/131856392/3f5398.pdf
    • https://cdn.shopify.com/s/files/1/0429/7854/1722/files/2345542982.pdf
    • https://cdn.shopify.com/s/files/1/0430/7386/3829/files/togagarodaxurix.pdf
    • https://cdn.shopify.com/s/files/1/0433/7709/8913/files/epic_emr_user_manual.pdf
    • https://cdn.shopify.com/s/files/1/0431/4251/2797/files/3658502461.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/24501063531.pdf
    • https://cdn.shopify.com/s/files/1/0439/2160/4763/files/95817015665.pdf
    • https://cdn.shopify.com/s/files/1/0432/3698/2943/files/71160957558.pdf
    • https://cdn.shopify.com/s/files/1/0435/3366/4408/files/95335771820.pdf
    • https://cdn.shopify.com/s/files/1/0428/6545/9366/files/40826691278.pdf
    • https://cdn.shopify.com/s/files/1/0432/2174/5823/files/4965454253.pdf
    • https://cdn.shopify.com/s/files/1/0435/4077/5071/files/56544653732.pdf
    • https://cdn.shopify.com/s/files/1/0434/7294/5312/files/kiniwasotaguxab.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00016b32.bin
2f32373152b86590eb5c993bf8dbb57d20fc33770b92bc1ec6b5fd985d660553
pdf-font-stream PDF embedded font (sfnt) at offset 0x16B32 2828 bytes
font_01_sfnt_off0001753b.bin
efd3b1bef0928ef7ddd4e45a4b80bd7b68fa81a34ae9e85d579e5ec028710ed4
pdf-font-stream PDF embedded font (sfnt) at offset 0x1753B 5608 bytes
font_02_sfnt_off00018863.bin
aaf7b683fb11219bf88f7c3b397d974af0630f310ba45defca30a631a953f883
pdf-font-stream PDF embedded font (sfnt) at offset 0x18863 11756 bytes