Malicious PDF — malware analysis report

Static analysis result for SHA-256 9fe151d40b79bbe6…

MALICIOUS

PDF

36.2 KB Created: 2020-09-19 21:05:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 03f320ba30c6ebe4e86d4d014f7167eb SHA-1: 9c1233ae257bc6a61ed13e78e05cb87cb377fd27 SHA-256: 9fe151d40b79bbe6a33123e2bafe3294461d9bd6e3bdadbb3d15868e7375b66f
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a heuristic firing for a malicious redirector link, specifically pointing to 'ttraff.com'. The document body, though heavily obfuscated, contains text related to 'triple beam balance worksheet answers' and the malicious URL itself, suggesting a lure to trick users into clicking the link. The presence of numerous other PDF links, many pointing to Shopify domains, indicates a link farm strategy, likely for SEO poisoning or to obscure the malicious destination. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=triple+beam+balance+worksheet+answers
    • http://dufodaze.vtk.co.nz/uploads/1/3/2/6/132695643/3961732.pdf
    • http://files.willettswelding.com/uploads/1/3/1/4/131437402/1778848.pdf
    • http://koxopimo.bzhanglab.com/uploads/1/3/0/9/130969186/retonuduxegugova.pdf
    • http://bopul.vigilantics.com/uploads/1/3/1/1/131164104/6947007.pdf
    • https://cdn.shopify.com/s/files/1/0430/2916/8282/files/airplane_english_movie_free.pdf
    • https://cdn.shopify.com/s/files/1/0436/0978/4482/files/65717118473.pdf
    • https://cdn.shopify.com/s/files/1/0463/5118/8125/files/wujimuletafeboso.pdf
    • https://904526ea-8b80-410d-a713-7974c6932f55.filesusr.com/ugd/9b7d8a_448299f4ce784f9996a301ed69597a8f.pdf?index=true
    • https://7a6f93d3-38f4-4d94-888d-48c52ae1a901.filesusr.com/ugd/7cefa9_58c6faa413104fb493489e1a43b21cb1.pdf?index=true
    • https://0a356b5f-edea-4b3d-83c5-2d73396b84e1.filesusr.com/ugd/8ba634_90d496557ff5469eb1901cacb82414ff.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004f2c.bin
dc2cace1db89d6ec1652d4eddc2aaa39b6d751afdd18cb4280dcf565cd4f1095
pdf-font-stream PDF embedded font (sfnt) at offset 0x4F2C 5416 bytes
font_01_sfnt_off0000617a.bin
eb0e3abbf58b08fb8c2dbe02c6b1e6c468a8a480ad702a33bccd78af04a83dfe
pdf-font-stream PDF embedded font (sfnt) at offset 0x617A 10132 bytes