Malicious PDF — malware analysis report

Static analysis result for SHA-256 81afd2ba8c14ef7d…

MALICIOUS

PDF

45.0 KB Created: 2020-09-03 00:32:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a6419e1ebed09175d4a2fee7c847db2a SHA-1: b4c7fed4ce95d5f9df028b26e7c3e55d9771acf0 SHA-256: 81afd2ba8c14ef7db07d7baa00999fbd3af17d2feed3a96887e1b03f133bf712
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.club/wix?keyword=cadence+report+%25E4%25B8%25AD%25E6%2596%2587'. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded links, many pointing to Shopify domains. The ML classifier also strongly flagged this PDF as malicious. The document body appears to be corrupted or obfuscated, but the presence of the malicious URL is the primary indicator of compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=cadence+report+%25E4%25B8%25AD%25E6%2596%2587
    • https://cdn.shopify.com/s/files/1/0439/2304/6555/files/53493347052.pdf
    • https://cdn.shopify.com/s/files/1/0430/9922/6265/files/39937916874.pdf
    • https://cdn.shopify.com/s/files/1/0431/5699/6247/files/76570390287.pdf
    • https://cdn.shopify.com/s/files/1/0436/0624/5539/files/3790933045.pdf
    • https://cdn.shopify.com/s/files/1/0435/6413/8651/files/jixinitokixi.pdf
    • https://static.usrfiles.com/ugd/b8c837_6be1c08ab6f04fba8c62b1b55f411067.pdf
    • https://static.usrfiles.com/ugd/0bcf16_1e503d46989242efa09fd080ad78c0ab.pdf
    • https://static.usrfiles.com/ugd/b8c837_d35862a6fabe4deaa45b4555f8f02bd8.pdf
    • https://static.usrfiles.com/ugd/b8c837_9af0223be4134b44aeaca6abddd61bdf.pdf
    • https://static.usrfiles.com/ugd/de02f3_ac3ce04fe138401f8af8531186e3b390.pdf
    • https://static.usrfiles.com/ugd/165585_acd6f5878a634cbe86c1f5bf99b51159.pdf
    • https://static.usrfiles.com/ugd/5ed537_18af9c6a29ad4768a6635fdff3878a71.pdf
    • https://static.usrfiles.com/ugd/b8c837_2b1b989530774fde974ad54fcf8eeda2.pdf
    • https://static.usrfiles.com/ugd/3f80ec_599f703071a14741b81d3666032ecfbd.pdf
    • https://static.usrfiles.com/ugd/12f4eb_77101fb85cdf4746ba606ca25509a333.pdf
    • https://static.usrfiles.com/ugd/72ed28_98fc96b3998246a3b357fd64ec676c1a.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000066c7.bin
293fe1ce95feff83484e80987484091b263439f192ea634ff14e983d3ccadefe
pdf-font-stream PDF embedded font (sfnt) at offset 0x66C7 3112 bytes
font_01_sfnt_off000071cc.bin
59641118919f0cf3ebc42aa25fd679a0eeb9b9b9a40b477375a0be120f404f09
pdf-font-stream PDF embedded font (sfnt) at offset 0x71CC 4764 bytes
font_02_sfnt_off00008207.bin
2e9d84a49bcb2e26769ee2c16fb44560a730ef81b0191a50a744227d988801a5
pdf-font-stream PDF embedded font (sfnt) at offset 0x8207 10304 bytes