Malicious PDF — malware analysis report

Static analysis result for SHA-256 8de6fd6123d59c67…

MALICIOUS

PDF

47.9 KB Created: 2020-07-31 04:21:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0cfc79031c879e4c882b1df5df76fa85 SHA-1: b00b35eca1c0bf9dcad6f12026c9713f86ae77e5 SHA-256: 8de6fd6123d59c675357a4ff7cd5880134e982aa973ad8014de68337705f3c27
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'ttraff.com'. It also exhibits characteristics of a PDF link farm, with numerous external links, many hosted on Shopify. The document body, though heavily obfuscated, contains keywords like 'Access database tutorial 2020 pdf' and metadata indicating it was generated by wkhtmltopdf, suggesting a lure to disguise the malicious intent. The primary attack pattern involves tricking users into clicking the malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=access+database+tutorial+2020+pdf
    • http://files.wyattnations.org/uploads/1/3/1/0/131070938/gajedojarewo-ditumugi.pdf
    • http://files.christiegrimes.com/uploads/1/3/1/4/131438313/tevebagatekuvuj_doxuvetum_zazepi_wujujorapere.pdf
    • http://files.bluegrassharmony.com/uploads/1/3/0/7/130776166/beffb386384e5.pdf
    • http://files.bookhivebeerclub.com/uploads/1/3/0/9/130969910/f65beae6b726.pdf
    • https://cdn.shopify.com/s/files/1/0427/5005/0460/files/98661576175.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/vawis.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/94448736580.pdf
    • https://cdn.shopify.com/s/files/1/0434/7727/0692/files/batomolisigarem.pdf
    • https://cdn.shopify.com/s/files/1/0431/7465/8197/files/semiposiponi.pdf
    • https://cdn.shopify.com/s/files/1/0429/2270/5055/files/57052843681.pdf
    • https://cdn.shopify.com/s/files/1/0431/6784/2459/files/55687666129.pdf
    • https://cdn.shopify.com/s/files/1/0429/3050/3843/files/xarirosabuzaxomigijovak.pdf
    • https://cdn.shopify.com/s/files/1/0430/6065/8330/files/89140520553.pdf
    • https://cdn.shopify.com/s/files/1/0434/1586/3447/files/61951143009.pdf
    • https://cdn.shopify.com/s/files/1/0434/3513/1046/files/wuboborek.pdf
    • https://cdn.shopify.com/s/files/1/0435/2511/1972/files/77021720640.pdf
    • https://cdn.shopify.com/s/files/1/0431/3268/2397/files/98867690459.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com/s/files/1/04

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007b61.bin
3db8e3fbef1a5f93e00e7e008e6d01a194027f3f50a7f1e2f6128750d4526be5
pdf-font-stream PDF embedded font (sfnt) at offset 0x7B61 5328 bytes
font_01_sfnt_off00008d84.bin
280c6f1105786477f040d4628cf941ce732b705d08f6aa10f1042340cae336ac
pdf-font-stream PDF embedded font (sfnt) at offset 0x8D84 10896 bytes