Malicious PDF — malware analysis report

Static analysis result for SHA-256 7d2f90c2c5d2aeb9…

MALICIOUS

PDF

55.3 KB Created: 2020-08-15 04:41:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c7f46c4bd6597b32f92f205ceb01bf89 SHA-1: 2633e64e0e5cf88e3b30b765ae68d2c07b8b2fa9 SHA-256: 7d2f90c2c5d2aeb963ee6782266d478475df99df2cff37e6445c545c0f817334
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. Additionally, it exhibits a PDF link farm pattern, with numerous links hosted on cdn.shopify.com, suggesting an attempt to manipulate search engine results or lure users to malicious sites. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=betaflight+configurator++mac
    • http://wodipikiz.gracechristianmusicfestival.com/uploads/1/3/1/4/131406687/7548030.pdf
    • https://cdn.shopify.com/s/files/1/0435/0862/9659/files/webesomirogo.pdf
    • https://cdn.shopify.com/s/files/1/0430/4509/3533/files/51086598775.pdf
    • https://cdn.shopify.com/s/files/1/0434/7972/8281/files/16482304662.pdf
    • https://cdn.shopify.com/s/files/1/0433/9813/5966/files/noxotowezitipogaruz.pdf
    • https://cdn.shopify.com/s/files/1/0430/9568/7317/files/veruzopinedeleva.pdf
    • https://cdn.shopify.com/s/files/1/0431/5276/9192/files/water_supply_reliability_theory.pdf
    • https://cdn.shopify.com/s/files/1/0434/0734/3772/files/chemistry_an_atoms_focused_approach.pdf
    • https://cdn.shopify.com/s/files/1/0433/6759/6184/files/webedomo.pdf
    • https://cdn.shopify.com/s/files/1/0431/5935/5556/files/pataferunimeduv.pdf
    • https://cdn.shopify.com/s/files/1/0438/0177/2192/files/sterling_night_hero.pdf
    • https://cdn.shopify.com/s/files/1/0435/2471/8746/files/91793035047.pdf
    • https://cdn.shopify.com/s/files/1/0437/0844/8919/files/71098412853.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000596c.bin
494b852e26cfe6a548b1d74813a8badf3c3bb37a64015a36c06278754af42b56
pdf-font-stream PDF embedded font (sfnt) at offset 0x596C 20516 bytes
font_01_sfnt_off00009b62.bin
0f3f92b803b07758b580e3fd4865ae4afcc196afd0cb9c8241465046ca08bd48
pdf-font-stream PDF embedded font (sfnt) at offset 0x9B62 5168 bytes
font_02_sfnt_off0000acc0.bin
5835287e2a69276135307e7743e26dc2ebd70ede2349641e41da8f34c31d953b
pdf-font-stream PDF embedded font (sfnt) at offset 0xACC0 10360 bytes