Malicious PDF — malware analysis report

Static analysis result for SHA-256 bdabf84bde69b20b…

MALICIOUS

PDF

52.0 KB Created: 2020-08-26 22:25:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 03038f28a2e858a291e33460f9dec331 SHA-1: ef7af072b5efb68a8b1b6fcbac7d9cf2a405e314 SHA-256: bdabf84bde69b20b1ef35fac20427b126a9263b00da415a4c98e6bd10e7d28ee
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a heuristic firing for a malicious redirector link, specifically pointing to 'ttraff.cc'. The document body, though heavily obfuscated, contains the same URL, suggesting it's the primary lure. This URL is likely used to redirect the user to a malicious site, potentially for further exploitation or credential harvesting. The presence of a large number of embedded links, many pointing to Shopify domains, indicates a link farm strategy, likely to improve SEO for malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=acrobat+dc+standard+installer
    • http://files.dynamicspinesportwellness.com/uploads/1/3/0/8/130813876/4935285.pdf
    • http://files.cintri.org/uploads/1/3/1/1/131163734/1aeb8bfc8338a.pdf
    • http://kajub.faultlinederby.org/uploads/1/3/0/7/130739593/9508609.pdf
    • http://files.leoinyourkitchen.com/uploads/1/3/0/7/130739810/xipolotogi-ruwawuve-surejeme-kakisiz.pdf
    • https://cdn.shopify.com/s/files/1/0431/6699/0498/files/navenemufufirofosesite.pdf
    • https://cdn.shopify.com/s/files/1/0432/2947/9076/files/polymerase_chain_reaction_introduction.pdf
    • https://cdn.shopify.com/s/files/1/0431/9064/8994/files/naliposo.pdf
    • https://cdn.shopify.com/s/files/1/0429/0658/3203/files/45844841593.pdf
    • https://cdn.shopify.com/s/files/1/0434/1753/4629/files/suvaxadoxolajala.pdf
    • https://cdn.shopify.com/s/files/1/0436/7033/9737/files/nosirovebilatotit.pdf
    • https://cdn.shopify.com/s/files/1/0429/1392/3228/files/warlock_guide_5e.pdf
    • https://cdn.shopify.com/s/files/1/0433/3427/1126/files/pomajusum.pdf
    • https://cdn.shopify.com/s/files/1/0432/5854/4292/files/las_almas_heridas_boris_cyrulnik.pdf
    • https://cdn.shopify.com/s/files/1/0437/5265/2961/files/bowflex_ultimate_2_manual.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000576a.bin
ed80b73e366b07ed55fcb18e42ceacf88a3360e67044a70402aaa10216252cd2
pdf-font-stream PDF embedded font (sfnt) at offset 0x576A 5236 bytes
font_01_sfnt_off000069d4.bin
e09aadf4e53448b56933a109d4f41a40b6078ca326518cb09f2287750cae5cf1
pdf-font-stream PDF embedded font (sfnt) at offset 0x69D4 4848 bytes
font_02_sfnt_off00007a46.bin
9d8857db41d77da6d925cf0edc3a04550760f044ab15e77f0b1d3e7022e2de7f
pdf-font-stream PDF embedded font (sfnt) at offset 0x7A46 10292 bytes
font_03_sfnt_off00009d9d.bin
1d240a0535f2140f7c954fae970985d54487e451ba4ee00a2f6f8a8e98c285da
pdf-font-stream PDF embedded font (sfnt) at offset 0x9D9D 16488 bytes
font_04_sfnt_off0000b42b.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0xB42B 4324 bytes