Malicious PDF — malware analysis report

Static analysis result for SHA-256 808c429c662c6f8e…

MALICIOUS

PDF

50.4 KB Created: 2020-08-30 13:13:41 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1b930084129cff93dbd0150401c509f9 SHA-1: f8f7aae7764a525f2b0e9b00cfacd55faba068e4 SHA-256: 808c429c662c6f8e5073542108b381bc2f1da1cd88e85401c2c42bb6a3cdb6b1
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document is identified as malicious by an ML classifier and contains numerous embedded links. One critical heuristic indicates that these links point to known malicious redirector infrastructure, specifically to 'ttraff.com'. The document body, though partially corrupted, suggests a lure related to a '2000 jeep grand cherokee service manual', likely to entice users to click on the malicious links. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=2000+jeep+grand+cherokee+service+manual
    • https://cdn.shopify.com/s/files/1/0431/1659/3312/files/41892429841.pdf
    • https://cdn.shopify.com/s/files/1/0427/9920/2467/files/kovudoratatabi.pdf
    • https://cdn.shopify.com/s/files/1/0433/4338/0631/files/army_promotion_board_bio.pdf
    • https://cdn.shopify.com/s/files/1/0448/4520/3618/files/effective_communication.pdf
    • https://static.usrfiles.com/ugd/b8c837_1df8a0a6591542ecab335419ce362a40.pdf
    • https://static.usrfiles.com/ugd/fd7405_f17b3bb1d5844f409d75043f9ff65699.pdf
    • https://static.usrfiles.com/ugd/b91566_0d00ebf1e6d14e3b89856b511a225b96.pdf
    • https://static.usrfiles.com/ugd/dfb5f8_8c436741c3454630b8fbbe1fa97fdca3.pdf
    • https://static.usrfiles.com/ugd/963627_7237e74c929f4edb8ff549b85e88e48d.pdf
    • https://cdn.shopify.com/s/files/1/0429/8883/0873/files/91465198654.pdf
    • https://cdn.shopify.com/s/files/1/0428/7394/6275/files/21091444364.pdf
    • https://cdn.shopify.com/s/files/1/0437/8771/4721/files/curriculum_innovation_definition.pdf
    • https://cdn.shopify.com/s/files/1/0434/4732/0728/files/rokimudozo.pdf
    • https://cdn.shopify.com/s/files/1/0437/3826/7809/files/army_strike_redeem_codes.pdf
    • https://cdn.shopify.com/s/files/1/0435/8019/4975/files/king_s_raid_clause_transcendence_guide.pdf
    • https://cdn.shopify.com/s/files/1/0432/7230/6846/files/teri_aankhon_ka_kajal_song_wapking.pdf
    • https://cdn.shopify.com/s/files/1/0428/0143/0695/files/wasekikevubate.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008507.bin
298fcdc8f62f8ce9c86f937e10eadf7bbf6a68926190ac6d6ab526508ca6180b
pdf-font-stream PDF embedded font (sfnt) at offset 0x8507 5868 bytes
font_01_sfnt_off000098d9.bin
83a2059c4855f63389ded27cade55fcbd45bd8f377429b67f3d79ee0c8c7cce6
pdf-font-stream PDF embedded font (sfnt) at offset 0x98D9 10388 bytes