Malicious PDF — malware analysis report

Static analysis result for SHA-256 d587b6f63580e586…

MALICIOUS

PDF

36.6 KB Created: 2020-09-01 03:53:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d65cc87ed4fcf312c5d1d5c5ace171b0 SHA-1: 385b70fc383c7a668503720141d4c6d6049306e8 SHA-256: d587b6f63580e586d06901780a24564ac9b623f5ec95b1a722b77725ff527118
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a link to a known malicious redirector, ttraff.cc, which is disguised as a 'Snakes and ladders template british council'. This heuristic, combined with the ML classifier flagging the PDF as malicious, strongly suggests a phishing or social engineering attack. The document body, though heavily obfuscated, contains the same lure text and the malicious URL, reinforcing the attack pattern. The presence of numerous other links to PDF files, while some are benign, indicates a potential link farm for SEO poisoning or to distribute further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=snakes+and+ladders+template+british+council
    • https://cdn.shopify.com/s/files/1/0432/3124/8542/files/54857727130.pdf
    • https://cdn.shopify.com/s/files/1/0430/7910/6724/files/iap_vaccination_schedule_2020.pdf
    • https://cdn.shopify.com/s/files/1/0427/4746/1788/files/75132974945.pdf
    • https://cdn.shopify.com/s/files/1/0438/9571/8040/files/97857436647.pdf
    • https://static.usrfiles.com/ugd/b11f6d_8cdff38359854553ba317da43ec28ea5.pdf
    • https://static.usrfiles.com/ugd/6924eb_6424751a764b43c4bc71168134030a4a.pdf
    • https://static.usrfiles.com/ugd/ae059d_d823e5e0fa704fb99addb2d4fa5c3449.pdf
    • https://static.usrfiles.com/ugd/136d07_8cbe1e78719a433a923a59f4df488fd6.pdf
    • https://static.usrfiles.com/ugd/b8c837_2dec5066c5b74e60b54c8eea77a3ec30.pdf
    • https://static.usrfiles.com/ugd/b8c837_6f64970ddd3842689cc60dc51f85cb25.pdf
    • https://static.usrfiles.com/ugd/f65518_5ce60f73d47d4af180fddb79be822bcf.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005147.bin
87df208d9f2b92a2f4162a368852157fb53ae62d6d56f3e27fc5d68671a82d11
pdf-font-stream PDF embedded font (sfnt) at offset 0x5147 5620 bytes
font_01_sfnt_off0000642c.bin
7280e48c9f8a1277c936c33981a36b3d9fa791b9042d3ae234450a85055b7506
pdf-font-stream PDF embedded font (sfnt) at offset 0x642C 9876 bytes