Malicious PDF — malware analysis report

Static analysis result for SHA-256 be5cf8256c262789…

MALICIOUS

PDF

76.3 KB Created: 2020-08-31 04:14:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1b477836c9899b3e24ef0badd9a04db9 SHA-1: 1629d628f4e1e46092d6a74b3a86f86885d7d78d SHA-256: be5cf8256c26278954ae7dfa5025d4b94ffe1764f4eaf55f293dd83444e97ee2
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. Additionally, it exhibits a PDF link farm heuristic, indicating a large number of embedded external links, with the first being to 'cdn.shopify.com'. The ML classifier also strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains the malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=mine+till+midnight+lisa+kleypas
    • https://cdn.shopify.com/s/files/1/0437/2417/7557/files/types_of_management_accounting_system.pdf
    • https://cdn.shopify.com/s/files/1/0431/4402/0125/files/calendario_completo_liga_mx_2020.pdf
    • https://cdn.shopify.com/s/files/1/0433/7519/8373/files/division_of_polynomials_examples_with_solutions.pdf
    • https://cdn.shopify.com/s/files/1/0433/0602/5128/files/tinirovorivulabudor.pdf
    • https://cdn.shopify.com/s/files/1/0433/4357/7256/files/free_brass_band_music.pdf
    • https://cdn.shopify.com/s/files/1/0429/6415/6582/files/new_dawn_fades_lyrics.pdf
    • https://cdn.shopify.com/s/files/1/0438/5187/4466/files/gubiwesadolek.pdf
    • https://cdn.shopify.com/s/files/1/0431/0017/6544/files/20175756456.pdf
    • https://static.usrfiles.com/ugd/b8c837_f7b99b6464864c338379f84ed86d63f1.pdf
    • https://static.usrfiles.com/ugd/4d400c_45263808338d4731b0af0426dccbceda.pdf
    • https://static.usrfiles.com/ugd/3ceeb9_16fd2fc9984646f2b78b3eaee40f060a.pdf
    • https://cdn.shopify.com/s/files/1/0432/4235/6904/files/82037680843.pdf
    • https://cdn.shopify.com/s/files/1/0434/8752/7078/files/78528886604.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ec7f.bin
dd8ccd465104f4e761bdadc82ff5da69d054e57e43af058260cb87c7eb11705a
pdf-font-stream PDF embedded font (sfnt) at offset 0xEC7F 5448 bytes
font_01_sfnt_off0000feee.bin
26f0ad3a0a9711b3ef2d28c6f8cff207a9cacc341f1704bee71a3db269da69b1
pdf-font-stream PDF embedded font (sfnt) at offset 0xFEEE 10568 bytes