Malicious PDF — malware analysis report

Static analysis result for SHA-256 7e06fcbc9738cb5c…

MALICIOUS

PDF

37.6 KB Created: 2020-08-27 21:37:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b6e3389ec57db38d2fce83c08dd5127f SHA-1: 21dc387838c283fdfd89c36cf33b823d96f97c91 SHA-256: 7e06fcbc9738cb5c414e287e52b246f44d8a360025f52ffa7ec376413c171c8b
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link farm and a malicious redirector, indicating a phishing or scam attempt. The document body, though heavily obfuscated, contains the URL that leads to the malicious redirector. The ML classifier strongly supports the malicious verdict. The primary attack vector appears to be a user clicking on the embedded link, which leads to the ttraff.cc redirector.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=cultural+respect+framework+australia
    • http://files.jeffreyholton.net/uploads/1/3/1/4/131437275/1cae2c859fe86.pdf
    • http://lifox.sallyant.com/uploads/1/3/0/7/130739873/3791855.pdf
    • https://cdn.shopify.com/s/files/1/0430/7720/6178/files/kafasux.pdf
    • https://cdn.shopify.com/s/files/1/0431/9733/3668/files/limologitomavezutagari.pdf
    • https://cdn.shopify.com/s/files/1/0434/1265/2194/files/minecraft_lucky_block_race_download.pdf
    • https://cdn.shopify.com/s/files/1/0429/5399/8487/files/velinobefofazopizerozuf.pdf
    • https://cdn.shopify.com/s/files/1/0472/3179/5365/files/alugueres_de_casa_do_esqui_stowe_ver.pdf
    • https://cdn.shopify.com/s/files/1/0432/6490/1270/files/minecraft._net_server_download.pdf
    • https://cdn.shopify.com/s/files/1/0431/6885/8280/files/34866175307.pdf
    • https://cdn.shopify.com/s/files/1/0434/7245/3797/files/rafari.pdf
    • https://cdn.shopify.com/s/files/1/0431/8376/7713/files/rca_voyager_pro.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/52665001447.pdf
    • https://cdn.shopify.com/s/files/1/0429/7188/9815/files/rotepevoropalud.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/xidab.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004809.bin
1e74ee359eb039f1c53666850f13a93134bc43681d32f78eac5a7706b37b65bd
pdf-font-stream PDF embedded font (sfnt) at offset 0x4809 5116 bytes
font_01_sfnt_off0000598e.bin
40e8c58fb3eb13ba1db00c263af2dd1b93829e9d70ae819e019d3455adc89535
pdf-font-stream PDF embedded font (sfnt) at offset 0x598E 9900 bytes
font_02_sfnt_off00007b5b.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0x7B5B 4324 bytes