Malicious PDF — malware analysis report

Static analysis result for SHA-256 be7967f591b441cf…

MALICIOUS

PDF

46.7 KB Created: 2020-08-29 18:33:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: dee4ff6ad43c1e630f4fb0f5a7644a03 SHA-1: fdaf828cda7a5f5264b0d8d567ef5664f92255b3 SHA-256: be7967f591b441cf42caf91ba977232752c8f9efcc7f98528468d4427194a7ef
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'ttraff.cc'. The document body, though heavily obfuscated, contains text related to 'anatomy and physiology crossword puzzle answers chapter 7' and includes the malicious URL. This suggests a social engineering lure to drive traffic to a malicious site. The presence of numerous other PDF links, many pointing to Shopify, indicates a link farm strategy, likely for SEO poisoning or to obscure the primary malicious destination.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=anatomy+and+physiology+crossword+puzzle+answers+chapter+7
    • https://cdn.shopify.com/s/files/1/0431/0863/0681/files/91808573376.pdf
    • https://cdn.shopify.com/s/files/1/0431/4395/4594/files/89401543636.pdf
    • https://cdn.shopify.com/s/files/1/0430/9381/9541/files/poxofifubagalegosazo.pdf
    • https://cdn.shopify.com/s/files/1/0440/9065/4870/files/borehole_water.pdf
    • https://cdn.shopify.com/s/files/1/0429/0668/1497/files/hallelujah_song_piano.pdf
    • https://static.usrfiles.com/ugd/b8c837_bd83b711650c46d0ace2eb252c52e830.pdf
    • https://static.usrfiles.com/ugd/b8c837_be047e588070491e8bf1849d02131b7c.pdf
    • https://static.usrfiles.com/ugd/b8c837_6f15608759e54404a0a0ecd47c394b6b.pdf
    • https://static.usrfiles.com/ugd/2f8cea_18a3dff1484a4ae198a3b4f6d4dab9b3.pdf
    • https://static.usrfiles.com/ugd/b8c837_9d68b757b6564f6597666d79b09c24aa.pdf
    • https://static.usrfiles.com/ugd/b8c837_335e42b09e474ea6aae944e6a41eac6f.pdf
    • https://static.usrfiles.com/ugd/b8c837_0efc339b98e747a992879437c9e52293.pdf
    • https://static.usrfiles.com/ugd/7ff653_bd49fe7103444507943e0af4f7282dd4.pdf
    • https://static.usrfiles.com/ugd/b8c837_86fd3b4a1b0e47df8cd87c2ef50731de.pdf
    • https://static.usrfiles.com/ugd/d2751c_5ba7d13be0a5466c8c200c1a6c9ffe58.pdf
    • https://static.usrfiles.com/ugd/b8c837_aa221773c22547fdb89987f057ae7911.pdf
    • https://static.usrfiles.com/ugd/12f4eb_49cc67ec881d46858ff201e00ddce84e.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000696f.bin
c516238570061860312f49e635334a59ad84ef8d6d94d7bc139c64118666d9ba
pdf-font-stream PDF embedded font (sfnt) at offset 0x696F 5680 bytes
font_01_sfnt_off00007cb3.bin
bd681320394682fc03da523658e160e01c965a9c06b0041c490fb17356f5a8d0
pdf-font-stream PDF embedded font (sfnt) at offset 0x7CB3 10080 bytes
font_02_sfnt_off00009ee6.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0x9EE6 4324 bytes