Malicious PDF — malware analysis report

Static analysis result for SHA-256 87f921e59a95974b…

MALICIOUS

PDF

46.9 KB Created: 2020-08-19 07:59:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cf3ff445c09f2d6be898dbcdb8821926 SHA-1: 78920521e51528c299ccd1ca3ac4e6a6102c0e8e SHA-256: 87f921e59a95974bda2104a84d6e3803cfde637dabb5701137431a9a8b6fc05d
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a critical heuristic firing for linking to known malicious redirector infrastructure, specifically pointing to 'ttraff.com'. The document body, though heavily obfuscated, contains the same URL, suggesting it's the primary lure. The presence of numerous external PDF links, many hosted on Shopify, indicates a link farm strategy, likely to obscure the malicious redirector or to appear legitimate. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=maglev+train+seminar+report+pdf
    • http://files.stjohnsecofin.com/uploads/1/3/2/6/132682119/pipekexug.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0432/7027/5236/files/bowesimoxuduvi.pdf
    • https://cdn.shopify.com/s/files/1/0431/3828/5725/files/42285949263.pdf
    • https://cdn.shopify.com/s/files/1/0433/5199/8623/files/welding_skills_workbook_answers.pdf
    • https://cdn.shopify.com/s/files/1/0430/0124/9955/files/16383154737.pdf
    • https://cdn.shopify.com/s/files/1/0431/3805/6354/files/11038375324.pdf
    • https://cdn.shopify.com/s/files/1/0431/5768/4375/files/17509795717.pdf
    • https://cdn.shopify.com/s/files/1/0450/3673/2566/files/69280388067.pdf
    • https://cdn.shopify.com/s/files/1/0436/4494/4542/files/activity_based_costing_definition.pdf
    • https://cdn.shopify.com/s/files/1/0435/9513/7187/files/1990500553.pdf
    • https://cdn.shopify.com/s/files/1/0454/7058/0902/files/34064226387.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006f9b.bin
6d095aeca97bc1f7df0118320aaf850c38a7d28cf3f5829b2ff7088c479baf41
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F9B 5428 bytes
font_01_sfnt_off000081fe.bin
51ebeec29509b87aa858d500e37ac8853184703d07d1f913ce36d8e1dc7764c0
pdf-font-stream PDF embedded font (sfnt) at offset 0x81FE 1800 bytes
font_02_sfnt_off00008a8c.bin
0fd2ef7efc0a5629a48a359c1f332da1d9d9536890c903b25fb4b9de21be754a
pdf-font-stream PDF embedded font (sfnt) at offset 0x8A8C 10628 bytes