Malicious PDF — malware analysis report

Static analysis result for SHA-256 beb276ff9bbb60fe…

MALICIOUS

PDF

44.9 KB Created: 2020-07-15 04:51:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: aa398f7b3a1179fb24100e4e882be3b5 SHA-1: 9be78b62fb75c083bcc17327b244b4e3fd45ae22 SHA-256: beb276ff9bbb60fec8cd177c3db569c9543136c882d5e3d0a6a8e1ceb1d8e45d
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.cc'. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded URLs, many hosted on Shopify. The ML classifier strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains metadata suggesting it was generated by wkhtmltopdf, a tool often used to create malicious PDFs.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wp3?keyword=gains+from+trade+pdf
    • http://files.jonataschimen.com/uploads/1/3/1/4/131483153/8937036.pdf
    • http://files.wlcbands.com/uploads/1/3/1/6/131607712/2769e0d94.pdf
    • http://files.monicasscarfs.com/uploads/1/3/1/6/131607054/zoziwadem.pdf
    • https://cdn.shopify.com/s/files/1/0429/1005/6615/files/tifanejavezogujigutabered.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/86593634255.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/34515707504.pdf
    • https://cdn.shopify.com/s/files/1/0431/0676/2903/files/19841033605.pdf
    • https://jorogoko.files.wordpress.com/2020/07/vetexobi.pdf
    • https://dizujased.files.wordpress.com/2020/07/32004685927.pdf
    • https://rudogatam.files.wordpress.com/2020/07/wimov.pdf
    • https://jufekam.files.wordpress.com/2020/07/51053406306.pdf
    • https://varaziwatu.files.wordpress.com/2020/06/zepariv.pdf
    • https://cdn.shopify.com/s/files/1/0430/8697/1029/files/gonawitowavivuva.pdf
    • https://cdn.shopify.com/s/files/1/0433/2906/1014/files/26401736944.pdf
    • https://cdn.shopify.com/s/files/1/0435/2029/5064/files/xagoluvemumofekubuvu.pdf
    • https://cdn.shopify.com/s/files/1/0427/9179/6902/files/33746109552.pdf
    • https://cdn.shopify.com/s/files/1/0430/0200/3609/files/jilakutu.pdf
    • https://cdn.shopify.com/s/files/1/0432/0195/3952/files/63452139836.pdf
    • https://cdn.shopify.com/s/files/1/0433/5036/0232/files/95643192635.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/rowogumidakedodovejizana.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://dizujased.files.wordpress.com/2020/07/32004685

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007360.bin
8d698d8261a9d6b53ee4a96627cd0a47eac0502acda494dd2045a9a79708a469
pdf-font-stream PDF embedded font (sfnt) at offset 0x7360 4972 bytes
font_01_sfnt_off00008429.bin
573ed01971614bd18d386edf15ae4a8d2cdfc021bd0edb443d11f0f994969984
pdf-font-stream PDF embedded font (sfnt) at offset 0x8429 9992 bytes