Malicious PDF — malware analysis report

Static analysis result for SHA-256 8774fb83d0fd11e3…

MALICIOUS

PDF

43.5 KB Created: 2020-08-22 13:45:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a3d4dc7e9b173de8b7da5caedc6bb50a SHA-1: 6fdf731015725461d557e40727401972d162f12d SHA-256: 8774fb83d0fd11e34db76c36f5d46babc09758372d8e67a8e5a481bffdcbf8ea
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a significant number of embedded links, with a heuristic identifying it as a PDF link farm. One of the primary links directs to a known malicious redirector service, ttraff.com, which is likely used to obscure the ultimate malicious destination. The presence of numerous Shopify links, while some are benign, contributes to the overall link farm characteristic. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=billabong+t+shirt+size+guide
    • http://files.davidwalshbowlmaker.com/uploads/1/3/1/8/131858540/45efa.pdf
    • http://files.windmillerequine.com/uploads/1/3/0/9/130969825/taporesenawo-fawavagivazelit-ligisose.pdf
    • https://cdn.shopify.com/s/files/1/0434/2287/5797/files/sediwanatepezesipifo.pdf
    • https://cdn.shopify.com/s/files/1/0432/9593/2584/files/autodesk_inventor_animation_tutorial.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/sogogetuxupoxex.pdf
    • https://cdn.shopify.com/s/files/1/0440/5598/6341/files/dejijimofeme.pdf
    • https://cdn.shopify.com/s/files/1/0435/8592/9375/files/legalipogamezuf.pdf
    • https://cdn.shopify.com/s/files/1/0427/8062/3015/files/goodness_of_god_bethel_chords.pdf
    • https://cdn.shopify.com/s/files/1/0432/7142/2102/files/10169557011.pdf
    • https://cdn.shopify.com/s/files/1/0428/2938/1791/files/bunexapijovi.pdf
    • https://cdn.shopify.com/s/files/1/0435/7708/2019/files/xalifagajaged.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/76410179135.pdf
    • https://cdn.shopify.com/s/files/1/0431/5312/9629/files/gejunibunowerajufafoxufoz.pdf
    • https://cdn.shopify.com/s/files/1/0437/1084/1000/files/43990559568.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005e59.bin
1b15c4dc12551d43d4e16c15c23ddc911f39f2050fc32e0216d434a5ea4f84b5
pdf-font-stream PDF embedded font (sfnt) at offset 0x5E59 5208 bytes
font_01_sfnt_off00006ff7.bin
865e4bdb58cbee6a353605895a6c6a7cb979e2f6123c7e10dd0965d2937a9beb
pdf-font-stream PDF embedded font (sfnt) at offset 0x6FF7 10328 bytes
font_02_sfnt_off00009307.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0x9307 4324 bytes