Malicious PDF — malware analysis report

Static analysis result for SHA-256 6776236943da3ff5…

MALICIOUS

PDF

46.6 KB Created: 2020-08-18 21:17:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 21a09b0d382624b9b57e427777593f16 SHA-1: a0170b9a9a8d16b2d3cd2a967eb0eb67b6b3d205 SHA-256: 6776236943da3ff588c4d08a977f9179d745d12f603f1a0fd7bda7692b7c2928
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. It also exhibits characteristics of a PDF link farm, with numerous embedded URLs, many of which are hosted on Shopify. The document body, though heavily obfuscated, contains the same lure text and URLs, suggesting an attempt to drive traffic to malicious infrastructure. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=ae+templates+free++videohive
    • http://files.opunakesurflifesaving.com/uploads/1/3/0/8/130814513/gezitowejukejekojuko.pdf
    • http://pipil.northwesternartreview.com/uploads/1/3/0/8/130874218/domevogif.pdf
    • http://files.cliomuse.com/uploads/1/3/1/3/131379049/3828294.pdf
    • http://files.andjru.com/uploads/1/3/0/9/130968993/midivizaginaw.pdf
    • http://files.flipmyfloridayard.com/uploads/1/3/2/6/132681812/43889.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0433/1811/6510/files/jexidekurojupakejupinu.pdf
    • https://cdn.shopify.com/s/files/1/0432/1234/1416/files/35915290699.pdf
    • https://cdn.shopify.com/s/files/1/0430/4162/0119/files/perixutojav.pdf
    • https://cdn.shopify.com/s/files/1/0434/5282/5750/files/29064798272.pdf
    • https://cdn.shopify.com/s/files/1/0430/9116/5333/files/59076131332.pdf
    • https://cdn.shopify.com/s/files/1/0438/7989/1099/files/47923049733.pdf
    • https://cdn.shopify.com/s/files/1/0429/8535/7463/files/67993864067.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/bugasodaliza.pdf
    • https://cdn.shopify.com/s/files/1/0432/0657/4240/files/wumezolemukesekipu.pdf
    • https://cdn.shopify.com/s/files/1/0459/0452/7514/files/guidepost_solutions_new_york.pdf
    • https://cdn.shopify.com/s/files/1/0430/0832/7829/files/aakasam_loni_chandamama_ringtone.pdf
    • https://cdn.shopify.com/s/files/1/0432/8351/3494/files/18079542708.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007770.bin
e15dbeb91d353478025f6edc32ae98b575453ca66c81642991a455e0fdad15e6
pdf-font-stream PDF embedded font (sfnt) at offset 0x7770 5332 bytes
font_01_sfnt_off0000896f.bin
15448f4cf62e07626a94631da081cad7aae0bda5fb95a68010392a81b7630ce7
pdf-font-stream PDF embedded font (sfnt) at offset 0x896F 10648 bytes