Malicious PDF — malware analysis report

Static analysis result for SHA-256 af6040c6e2af19fc…

MALICIOUS

PDF

50.5 KB Created: 2020-08-04 21:54:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a062407d0cf2a670b1beb464ab3c4574 SHA-1: a8e076b9bc76373c90ff43c142df8c408eb02ed8 SHA-256: af6040c6e2af19fc9fb157268504e86ada0087120956866541b2d8722cce6f44
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded links, many pointing to Shopify domains. The ML classifier also strongly flagged this PDF as malicious. The primary attack vector appears to be directing users to malicious infrastructure via the embedded link, likely for phishing or further malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=artistry+signature+select+personalized+serum+pdf
    • http://files.johnsimmonline.com/uploads/1/3/0/7/130738504/woxokumu_miroz.pdf
    • http://files.wypta.org/uploads/1/3/1/6/131637814/woxulas.pdf
    • http://files.mountainwesttlod.org/uploads/1/3/1/6/131606631/kerusi.pdf
    • https://cdn.shopify.com/s/files/1/0433/3980/8922/files/zedomasemogune.pdf
    • https://cdn.shopify.com/s/files/1/0435/3651/5224/files/52178456291.pdf
    • https://cdn.shopify.com/s/files/1/0433/5170/3706/files/43329123437.pdf
    • https://cdn.shopify.com/s/files/1/0428/6713/0534/files/51530844288.pdf
    • https://cdn.shopify.com/s/files/1/0431/2553/8973/files/john_deere_sx75_manual.pdf
    • https://cdn.shopify.com/s/files/1/0431/1387/3569/files/rizut.pdf
    • https://cdn.shopify.com/s/files/1/0438/6599/7472/files/gentoo_install_script.pdf
    • https://cdn.shopify.com/s/files/1/0429/9731/7783/files/56546557416.pdf
    • https://cdn.shopify.com/s/files/1/0437/5651/9576/files/tegofoxejolodoliloteduv.pdf
    • https://cdn.shopify.com/s/files/1/0441/3505/5512/files/93332008268.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/vuvitew.pdf
    • https://cdn.shopify.com/s/files/1/0435/3002/7157/files/fodisokezulipufefa.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000073b9.bin
27b668e3ac5f0ffc3e7fb8e85209c6a32f93fbb7490c31fb66ae1eb8c12960b8
pdf-font-stream PDF embedded font (sfnt) at offset 0x73B9 5616 bytes
font_01_sfnt_off000086d5.bin
6553810983eb2c217da1baa9f4fc386ec09aee045bc5b1454cc045cf25198219
pdf-font-stream PDF embedded font (sfnt) at offset 0x86D5 6096 bytes
font_02_sfnt_off00009684.bin
d340538c892b0a8dbdbe44f5e08dd27dc43d0481821adbcc6b3a0e1e31669e45
pdf-font-stream PDF embedded font (sfnt) at offset 0x9684 10640 bytes