Malicious PDF — malware analysis report

Static analysis result for SHA-256 7d0bd6de7b196e95…

MALICIOUS

PDF

42.2 KB Created: 2020-09-07 13:41:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 02e89bab37aa91a1629bb5448bc661e2 SHA-1: a857a71b93308554d0ead6b36da573b124b02a3c SHA-256: 7d0bd6de7b196e95275817c13bc21febb595d5cd39f2e38f9316c3aa48b0435c
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/wix?keyword=bookmarks+firefox+android+export'. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded links, many hosted on Shopify. The ML classifier also strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains the malicious URL, suggesting a lure to a phishing or malware distribution site.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=bookmarks+firefox+android+export
    • https://cdn.shopify.com/s/files/1/0427/4287/4278/files/chief_examiner_s_report_on_english_language.pdf
    • https://cdn.shopify.com/s/files/1/0448/5352/6690/files/android_10_emoji_update.pdf
    • https://cdn.shopify.com/s/files/1/0443/0761/1804/files/risijasibizivavenositi.pdf
    • https://cdn.shopify.com/s/files/1/0436/9973/2633/files/9098544591.pdf
    • https://cdn.shopify.com/s/files/1/0431/5512/8477/files/bezuzi.pdf
    • https://cdn.shopify.com/s/files/1/0430/7389/6602/files/james_stewart_early_transcendentals.pdf
    • https://cdn.shopify.com/s/files/1/0431/7288/8742/files/flower_names_and_pictures.pdf
    • https://cdn.shopify.com/s/files/1/0429/8326/0314/files/zupowebelamiramozader.pdf
    • https://static.usrfiles.com/ugd/0d9a50_c2b21c4f601e42608dee0e1c6069b52b.pdf
    • https://static.usrfiles.com/ugd/77941b_d3db8a9fb55c499380f94d3880e0d33c.pdf
    • https://static.usrfiles.com/ugd/ef7486_2c7a2057cebf42cb8b936faa4a50fe6e.pdf
    • https://static.usrfiles.com/ugd/df73ab_2bee6617e76d4f7b94754fcfa41caa87.pdf
    • https://static.usrfiles.com/ugd/b8c837_fb53133584154903b1f367876c521722.pdf
    • https://static.usrfiles.com/ugd/21e6f2_471432780e38443ea8fa287c2b0ddcbf.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005cd5.bin
59e4edd191e715925d33f50c7846265841f0df670fb758accfb092d87ebd63f7
pdf-font-stream PDF embedded font (sfnt) at offset 0x5CD5 5336 bytes
font_01_sfnt_off00006ee3.bin
21a7146106e2ad29a4dcc6aa55cee169416400570e2b3d493b6d071cb256f2f3
pdf-font-stream PDF embedded font (sfnt) at offset 0x6EE3 1936 bytes
font_02_sfnt_off00007825.bin
ea47359950b4d3f6709c83ed028e528fda3a2f9e5f35e1af7b6b3763ade394b1
pdf-font-stream PDF embedded font (sfnt) at offset 0x7825 10460 bytes