Malicious PDF — malware analysis report

Static analysis result for SHA-256 9a09a262f6514628…

MALICIOUS

PDF

46.9 KB Created: 2020-08-21 13:32:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e6876c894abc7ed5215f4aa284509d5a SHA-1: 208ea9904c42de06ccf1d2baa25742b7453e9fbc SHA-256: 9a09a262f6514628b60c033d130a4b8a64e46dd5a3dc43317e7c4a99bfc55aa7
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. Additionally, it exhibits a PDF link farm heuristic, with numerous links to Shopify-hosted PDFs, suggesting an attempt to obscure malicious destinations or engage in SEO manipulation for traffic. The ML classifier also strongly flagged this PDF as malicious. The primary malicious URL identified is https://ttraff.com/pify?keyword=sleep+deprivation+and+academic+performance+theory.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=sleep+deprivation+and+academic+performance+theory
    • http://files.microbeautybykaylen.com/uploads/1/3/0/8/130813639/49316954678.pdf
    • http://files.newtonwoodcraft.com/uploads/1/3/0/8/130874222/d1134.pdf
    • http://simige.mwcatlanta.org/uploads/1/3/2/7/132712116/vusugituxone_nexinaxavubudiz_xofuguf_wadinasufa.pdf
    • http://files.s-jandhyala.com/uploads/1/3/0/7/130775953/8497883.pdf
    • https://cdn.shopify.com/s/files/1/0431/2891/4074/files/english_moral_stories_with_pictures.pdf
    • https://cdn.shopify.com/s/files/1/0430/6855/5415/files/69794430513.pdf
    • https://cdn.shopify.com/s/files/1/0431/2937/2832/files/bukarulukozigusabopefij.pdf
    • https://cdn.shopify.com/s/files/1/0436/0853/9299/files/14146434223.pdf
    • https://cdn.shopify.com/s/files/1/0459/9054/3519/files/free_oxford_english_dictionary_format.pdf
    • https://cdn.shopify.com/s/files/1/0432/8351/3494/files/xoxoxomipixoboguletududi.pdf
    • https://cdn.shopify.com/s/files/1/0430/0655/8359/files/99457821650.pdf
    • https://cdn.shopify.com/s/files/1/0435/7524/7003/files/zepaxekazedokiken.pdf
    • https://cdn.shopify.com/s/files/1/0431/7410/1160/files/wordpress_private_page.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006d11.bin
c9983a2cb173a4490d62fc53289110f9710699fdc6ec55523580e560cbda3df1
pdf-font-stream PDF embedded font (sfnt) at offset 0x6D11 5480 bytes
font_01_sfnt_off00007f93.bin
8b305b4ebd04d33041b54d999284e05a11842e2a3de5809936067d42fe95d5a2
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F93 14912 bytes