Malicious PDF — malware analysis report

Static analysis result for SHA-256 c03317e222d0e446…

MALICIOUS

PDF

52.6 KB Created: 2020-09-03 09:08:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a77d58e54b7b39f1e8c6edbc31479c0b SHA-1: 06adc7bb3123e61757a25cc9b937facd0d32b856 SHA-256: c03317e222d0e4462bb70c570dacdea7519d01f146482f2d870d005feb3c5036
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains numerous embedded links, a technique often used in SEO link farms to artificially inflate search engine rankings or to obscure malicious destinations. One of the primary links directs to a known malicious redirector, ttraff.com, which is likely used to funnel victims to further malicious content. The document body, though heavily obfuscated, contains text related to sheet music and the malicious URL, suggesting a lure to trick users into clicking the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=fairy+tail+slow+theme+flute+sheet+music
    • https://cdn.shopify.com/s/files/1/0431/7164/3554/files/43902380297.pdf
    • https://cdn.shopify.com/s/files/1/0430/8120/3861/files/alimentacion_saludable_vegetariana.pdf
    • https://cdn.shopify.com/s/files/1/0435/3625/3087/files/mastering_physics_14th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0428/6355/8815/files/harmony_650_setup.pdf
    • https://cdn.shopify.com/s/files/1/0429/9476/1877/files/wexurosodimakukex.pdf
    • https://cdn.shopify.com/s/files/1/0433/0012/6880/files/75132030903.pdf
    • https://cdn.shopify.com/s/files/1/0431/3884/2779/files/54225330325.pdf
    • https://cdn.shopify.com/s/files/1/0433/0582/8520/files/77680572649.pdf
    • https://cdn.shopify.com/s/files/1/0431/1223/5159/files/daxaja.pdf
    • https://cdn.shopify.com/s/files/1/0431/6515/5489/files/wagenawixin.pdf
    • https://cdn.shopify.com/s/files/1/0428/7932/0223/files/ximabuwokub.pdf
    • https://cdn.shopify.com/s/files/1/0462/2024/7194/files/sepitumonizav.pdf
    • https://cdn.shopify.com/s/files/1/0435/5362/0136/files/kovutez.pdf
    • https://static.usrfiles.com/ugd/b41a9a_c3adbceb83a1481fac323e25e5a3ac83.pdf
    • https://static.usrfiles.com/ugd/9f69bd_77a18584e93e4c83ad08001760842054.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com/s/files/1/0431/651

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007525.bin
b0d2c250083d8a9af084d233e88a4fb0268f6e9a5a766a6e47c4b9547cff45de
pdf-font-stream PDF embedded font (sfnt) at offset 0x7525 4288 bytes
font_01_sfnt_off00008447.bin
0e9250a348e6d4916d2b542f3bbe984a20592ce5d60a193b0292e82ff3c9c7a3
pdf-font-stream PDF embedded font (sfnt) at offset 0x8447 5272 bytes
font_02_sfnt_off00009624.bin
3d5e7a8dcceeff7dd20e2cfbea0d376899ab62fb4f4ca88c0f3bbb6aa71cfb11
pdf-font-stream PDF embedded font (sfnt) at offset 0x9624 14972 bytes