Malicious PDF — malware analysis report

Static analysis result for SHA-256 d20c2cb46dafd91a…

MALICIOUS

PDF

42.3 KB Created: 2020-08-05 21:16:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 980046d02e961b73a11cdacc82565d18 SHA-1: e1f13c7adbb51e90972fa726868a55ea69e6c598 SHA-256: d20c2cb46dafd91ae2b589a81999b3fef825d745b37610129182ac32f94709bf
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

This PDF document contains numerous embedded links, including one pointing to a known malicious redirector at 'https://ttraff.com/wb?keyword=keurig%20single%20cup%20instruction%20manual'. The document body, though heavily obfuscated, also contains this URL, suggesting a lure to trick users into clicking the link. The presence of a large number of other PDF links, many hosted on Shopify, indicates a potential SEO poisoning or link farm tactic to distribute malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wb?keyword=keurig%20single%20cup%20instruction%20manual
    • http://files.clarelouiseburnett.com/uploads/1/3/1/0/131069763/raros-wijeluz-sutor-lojawedorogof.pdf
    • http://files.oobmaps.org/uploads/1/3/1/4/131453950/populafujazalu.pdf
    • http://files.killernailzzz.com/uploads/1/3/2/6/132681378/7b031ca526.pdf
    • http://files.zenoacton.com/uploads/1/3/1/4/131409794/ridegofew-pupojoxiba-nivefevomopowu.pdf
    • http://files.eastcoastvintagemx.com/uploads/1/3/0/7/130738806/rovozurale.pdf
    • https://cdn.shopify.com/s/files/1/0435/5702/8001/files/problem_solving_cognitive_psychology.pdf
    • https://cdn.shopify.com/s/files/1/0433/3889/1419/files/97462535562.pdf
    • https://cdn.shopify.com/s/files/1/0434/6154/2054/files/44199607077.pdf
    • https://cdn.shopify.com/s/files/1/0447/1295/1961/files/mcp61pm-_gm_manual.pdf
    • https://cdn.shopify.com/s/files/1/0429/9633/4753/files/luzon.pdf
    • https://cdn.shopify.com/s/files/1/0428/2312/3100/files/advaita_vedanta.pdf
    • https://cdn.shopify.com/s/files/1/0431/8111/3506/files/discrete_mathematics_8th_edition_richard_johnsonbaugh.pdf
    • https://cdn.shopify.com/s/files/1/0433/2303/1720/files/rebuvuges.pdf
    • https://cdn.shopify.com/s/files/1/0436/0932/5730/files/faregojotokaw.pdf
    • https://cdn.shopify.com/s/files/1/0434/5289/1298/files/21323713321.pdf
    • https://cdn.shopify.com/s/files/1/0434/3159/2092/files/management_of_antepartum_hemorrhage.pdf
    • https://cdn.shopify.com/s/files/1/0428/6336/2204/files/ansilvund_excavation_first_puzzle.pdf
    • https://cdn.shopify.com/s/files/1/0447/3847/8229/files/battery_charging_voltage_chart.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006692.bin
634cd3e23c1c7c5d02a6702ce305abf0fd0e2dfc054d654a07ac62c936e4afa5
pdf-font-stream PDF embedded font (sfnt) at offset 0x6692 5224 bytes
font_01_sfnt_off0000784d.bin
3288b07d57a0f016642b260fdcf6cd133f1bcab0923165dd3456701a3710cfdd
pdf-font-stream PDF embedded font (sfnt) at offset 0x784D 10472 bytes