Malicious PDF — malware analysis report

Static analysis result for SHA-256 82ace92fed451e62…

MALICIOUS

PDF

115.1 KB Created: 2020-09-01 02:28:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b8311ca2306bfb81428df83d2a688c89 SHA-1: eaf5c74d908d631891d3e2949ba19b5698956668 SHA-256: 82ace92fed451e62b1cf67e83253a7cf6e6e697febb80c5613adc04a3eea6c69
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/wix?keyword=aiag+msa+manual+4th+edition'. This link is embedded within the document body, suggesting a social engineering lure to trick the user into clicking it. The ML classifier also strongly flagged this PDF as malicious. The presence of numerous external PDF links, while some are benign, indicates a link farm strategy, likely to obscure the malicious redirector.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=aiag+msa+manual+4th+edition
    • https://cdn.shopify.com/s/files/1/0437/4082/3701/files/50037459249.pdf
    • https://cdn.shopify.com/s/files/1/0433/2303/1720/files/gudumowagepupepefatefuzal.pdf
    • https://cdn.shopify.com/s/files/1/0428/5943/0047/files/87322134083.pdf
    • https://static.usrfiles.com/ugd/67f5f7_967df44628dc4f9aaa1b1db98361b85d.pdf
    • https://static.usrfiles.com/ugd/b8c837_6422be812c0c43898afed07fbb5b8c8e.pdf
    • https://static.usrfiles.com/ugd/07e02c_be6141d0ddad4ee2b45f9f24c1b2d419.pdf
    • https://cdn.shopify.com/s/files/1/0433/8984/5671/files/why_did_you_choose_accounting_career_answers.pdf
    • https://cdn.shopify.com/s/files/1/0432/3275/5875/files/windansea_surf_cam.pdf
    • https://cdn.shopify.com/s/files/1/0429/5986/3961/files/jareguvukuzeji.pdf
    • https://cdn.shopify.com/s/files/1/0430/8277/6729/files/4428889347.pdf
    • https://cdn.shopify.com/s/files/1/0432/9806/2501/files/article_exercise_download.pdf
    • https://cdn.shopify.com/s/files/1/0428/4016/2467/files/31906091954.pdf
    • https://cdn.shopify.com/s/files/1/0428/4933/7507/files/rupitebevom.pdf
    • https://cdn.shopify.com/s/files/1/0430/7258/5888/files/nuwagalujoniwelavemamu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000173cc.bin
16350ac7c4ada5d78b2b9460e59e336dd550a6fa45f2559dff5bdc62810944aa
pdf-font-stream PDF embedded font (sfnt) at offset 0x173CC 3072 bytes
font_01_sfnt_off00017fc7.bin
5f7d372d83e4518e6b6ff419b5ab29f2d65cc4ab6cf546f52e1a99544113318d
pdf-font-stream PDF embedded font (sfnt) at offset 0x17FC7 5220 bytes
font_02_sfnt_off0001916e.bin
4251b97d468073ebe56e5338c76a746cccf0d8f3827b4f1a1855b1e32ee58342
pdf-font-stream PDF embedded font (sfnt) at offset 0x1916E 14608 bytes