Malicious PDF — malware analysis report

Static analysis result for SHA-256 a40109670b75d765…

MALICIOUS

PDF

43.7 KB Created: 2020-08-19 18:44:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 15ae2fc9dc54632cc89da4b6761602bf SHA-1: f92de39ce101ab6705c5db9269303f2f57549e07 SHA-256: a40109670b75d76564bb953f89a967c3bd5bfc6847d7d114b47bfb7d6835fef2
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a link to a known malicious redirector, ttraff.com, which is likely used to obscure the final destination of the malicious payload. The document body, though partially corrupted, contains the same text as the URL's keyword parameter, suggesting a direct lure. The presence of numerous other PDF links, many hosted on Shopify, indicates a link farm strategy, potentially for SEO poisoning or distributing further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=im+looking+forward+to+see+you+answer
    • http://files.rocnap.com/uploads/1/3/0/7/130776120/sezaxap_nebeb.pdf
    • http://puvuwupa.unityroyaloak.org/uploads/1/3/1/3/131379732/dd07873d2ef.pdf
    • https://cdn.shopify.com/s/files/1/0431/8547/1656/files/73657786827.pdf
    • https://cdn.shopify.com/s/files/1/0437/9469/4304/files/warhammer_40k_necron_codex_6th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0431/3199/4280/files/somuluw.pdf
    • https://cdn.shopify.com/s/files/1/0433/4298/7423/files/93818982471.pdf
    • https://cdn.shopify.com/s/files/1/0433/0982/6213/files/33775241039.pdf
    • https://cdn.shopify.com/s/files/1/0435/8035/8811/files/xofaxigemigukaw.pdf
    • https://cdn.shopify.com/s/files/1/0437/7139/6257/files/96196390733.pdf
    • https://cdn.shopify.com/s/files/1/0428/8764/3303/files/how_to_install_sql_server_management_tools.pdf
    • https://cdn.shopify.com/s/files/1/0435/2465/3224/files/babibu.pdf
    • https://cdn.shopify.com/s/files/1/0435/3612/2008/files/33043510039.pdf
    • https://cdn.shopify.com/s/files/1/0427/7354/5116/files/text_document_to_converter_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0432/1551/9912/files/43480643593.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006cbc.bin
1bdca91d8d81305d4723fa489f2325fe5bdce2e6372a28a853584e05a00a0ff6
pdf-font-stream PDF embedded font (sfnt) at offset 0x6CBC 5420 bytes
font_01_sfnt_off00007f24.bin
d5686acef1a40279c5c9a129b93c9d7d577c019cc83e3178cab27ec6aad7a9df
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F24 10120 bytes