Malicious PDF — malware analysis report

Static analysis result for SHA-256 87a115c4e4bdba63…

MALICIOUS

PDF

45.4 KB Created: 2020-09-03 19:58:43 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c3161ef362deac808e6e5d237e8c6065 SHA-1: 6dcc60b3468239a3e4697db135c1d73f390ffaf0 SHA-256: 87a115c4e4bdba630446303762f1dd652f2f9a46c305531dbffa43712a8f880b
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.link/wix?keyword=blank+sheet+music+a4'. Additionally, it features a PDF link farm with numerous links hosted on cdn.shopify.com, suggesting an attempt to obscure the final malicious destination. The ML classifier also strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains the redirector URL, reinforcing the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=blank+sheet+music+a4
    • https://cdn.shopify.com/s/files/1/0427/7328/2983/files/gajaduvemugupiron.pdf
    • https://cdn.shopify.com/s/files/1/0432/9350/7737/files/coffee_grinder_manual_nz.pdf
    • https://cdn.shopify.com/s/files/1/0432/1994/3579/files/5747784252.pdf
    • https://cdn.shopify.com/s/files/1/0432/5189/2381/files/sample_abstract_chemistry_lab_report.pdf
    • https://cdn.shopify.com/s/files/1/0437/2935/4903/files/21482942104.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/44994208471.pdf
    • https://cdn.shopify.com/s/files/1/0433/3748/2405/files/79528156383.pdf
    • https://cdn.shopify.com/s/files/1/0447/3955/9578/files/lokosigakesukes.pdf
    • https://cdn.shopify.com/s/files/1/0465/2515/3430/files/70612189497.pdf
    • https://cdn.shopify.com/s/files/1/0434/5013/8784/files/html_to_converter_open_source.pdf
    • https://static.usrfiles.com/ugd/c0b427_c8229eb8be1e44c6a927f61e9903f725.pdf
    • https://static.usrfiles.com/ugd/d7ba0f_848244b19ddd45028ceef97a473ef7e0.pdf
    • https://static.usrfiles.com/ugd/b8c837_451a9e4708e1493eac691ea5b6dd5fdf.pdf
    • https://static.usrfiles.com/ugd/22bf55_fbe937d1ef5145c39f39f98a26a5447f.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com/s/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000062ef.bin
fb2948cd82ee9e21e92b184d2602bfd31c1d8a5ee934155d56ac5ceecb72d2f4
pdf-font-stream PDF embedded font (sfnt) at offset 0x62EF 6648 bytes
font_01_sfnt_off00007367.bin
9124b72a92a1d09bb07944cb802339daa2c9fcf54a052063c3fc446b084dd502
pdf-font-stream PDF embedded font (sfnt) at offset 0x7367 5144 bytes
font_02_sfnt_off000084ca.bin
db135abc7a7c1fdee8cb6b1ba790c0a63f016ac92234dd8cd3fcdb3fd9715b38
pdf-font-stream PDF embedded font (sfnt) at offset 0x84CA 10352 bytes