Malicious PDF — malware analysis report

Static analysis result for SHA-256 83ef83f7eac49f9e…

MALICIOUS

PDF

41.4 KB Created: 2020-09-02 13:24:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 15d5e8b92dd9d20e189a31c006d5b95d SHA-1: 8e2a247843834c6d53f6e482b5067fc814c8b3f8 SHA-256: 83ef83f7eac49f9e3147b1c1e8c7044fa850b7d64b03c41eb3d57297cd9844ef
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a link to a known malicious redirector infrastructure, ttraff.com, disguised as a download for music notation software. The document body and embedded URLs further reinforce this lure, directing users to potentially malicious content hosted on shopify.com. The ML classifier strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=music+notation+software+free
    • https://cdn.shopify.com/s/files/1/0430/2992/1943/files/mathematical_reasoning_writing_and_proof.pdf
    • https://cdn.shopify.com/s/files/1/0431/4018/6279/files/bacteriologia_y_virologia_medica.pdf
    • https://cdn.shopify.com/s/files/1/0439/5086/6590/files/2013_chrysler_town_and_country_touring_l_owners_manual.pdf
    • https://cdn.shopify.com/s/files/1/0427/9376/2975/files/xasuxamonunilagabuxujur.pdf
    • https://cdn.shopify.com/s/files/1/0432/1270/1854/files/vubewudox.pdf
    • https://cdn.shopify.com/s/files/1/0431/2619/4342/files/tufuwejutimivok.pdf
    • https://cdn.shopify.com/s/files/1/0430/8706/9348/files/99169618800.pdf
    • https://cdn.shopify.com/s/files/1/0427/6636/8935/files/academic_reading_and_writing_book.pdf
    • https://cdn.shopify.com/s/files/1/0435/2311/3119/files/tower_200_exercise_chart.pdf
    • https://cdn.shopify.com/s/files/1/0431/2684/9700/files/gosefijogigoga.pdf
    • https://cdn.shopify.com/s/files/1/0432/6480/2982/files/23760960363.pdf
    • https://cdn.shopify.com/s/files/1/0429/8083/5482/files/alvaro_mutis_poemas.pdf
    • https://cdn.shopify.com/s/files/1/0435/3415/5928/files/46243002701.pdf
    • https://cdn.shopify.com/s/files/1/0435/4995/0111/files/adjectives_year_1_worksheet.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006523.bin
0ea27b74328af32f6c3c1ee3085920f0d91182d93b4bdafd788f6eb766aafa31
pdf-font-stream PDF embedded font (sfnt) at offset 0x6523 4940 bytes
font_01_sfnt_off00007621.bin
8591a011c1078963f4d49447e2d9b74542bbfd7512ac5667c5784bc0ab18007e
pdf-font-stream PDF embedded font (sfnt) at offset 0x7621 10348 bytes