Malicious PDF — malware analysis report

Static analysis result for SHA-256 8eaf638f7a225df8…

MALICIOUS

PDF

44.2 KB Created: 2020-07-31 18:05:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 27b10f7179a83513e1acfc56f4e8ce63 SHA-1: f533de3ab48b021fb3592f5bde08d187d74e4b18 SHA-256: 8eaf638f7a225df89c24c9bfac4c2efe5fdfa5ab89a5d4a3df378dba74be03e8
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.com/pify?keyword=pocket+tank+deluxe+free'. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded links to other PDF files hosted on various domains, including multiple Shopify subdomains. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample, but the presence of the malicious redirector and link farm suggests a phishing or SEO poisoning attack vector.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=pocket+tank+deluxe+free
    • http://files.bakingbeast.com/uploads/1/3/0/7/130775145/jarijilaxokerizo.pdf
    • http://files.zackbacak.com/uploads/1/3/1/3/131398134/c9574.pdf
    • http://files.avayogabodywear.com/uploads/1/3/1/8/131856290/difimij.pdf
    • http://files.if-airfranceklmva.com/uploads/1/3/1/4/131454262/9676368.pdf
    • http://files.mandolinarmrests.com/uploads/1/3/0/8/130814861/2642522.pdf
    • https://cdn.shopify.com/s/files/1/0427/9474/6023/files/vexitagiwi.pdf
    • https://cdn.shopify.com/s/files/1/0434/8346/3832/files/45583405560.pdf
    • https://cdn.shopify.com/s/files/1/0437/6877/4814/files/sutusadubikapijujenive.pdf
    • https://cdn.shopify.com/s/files/1/0441/1208/5144/files/44904023529.pdf
    • https://cdn.shopify.com/s/files/1/0438/5167/7856/files/27354448413.pdf
    • https://cdn.shopify.com/s/files/1/0433/5498/0505/files/56439886943.pdf
    • https://cdn.shopify.com/s/files/1/0435/7872/0414/files/87830805441.pdf
    • https://cdn.shopify.com/s/files/1/0433/4062/8133/files/sefosivasatamexaramafogo.pdf
    • https://cdn.shopify.com/s/files/1/0429/5501/4297/files/60736405495.pdf
    • https://cdn.shopify.com/s/files/1/0431/4234/8949/files/sibemanazatatenaxopo.pdf
    • https://cdn.shopify.com/s/files/1/0430/9906/2421/files/gutazofeku.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007175.bin
7b8f57a3bed1bf445aebbaf00287188520248a84b904035b213bc6dba0d56473
pdf-font-stream PDF embedded font (sfnt) at offset 0x7175 4972 bytes
font_01_sfnt_off00008277.bin
a027416adce39f4197f05c528568d0ccd7b3f4e89cabf2c4e94d6305ca0293ed
pdf-font-stream PDF embedded font (sfnt) at offset 0x8277 9836 bytes