Malicious PDF — malware analysis report

Static analysis result for SHA-256 d8255e67be504c6f…

MALICIOUS

PDF

96.1 KB Created: 2020-09-20 23:59:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a25c6e12ab8fa58b7cb934532fa37047 SHA-1: 0c084925f7f11600f6d4163b5f2e5551911f98cf SHA-256: d8255e67be504c6f602f880b03ea2263e8f5fb89b69148590e5b967350a19269
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a heuristic firing for a malicious redirector link, which is further supported by the embedded URL pointing to 'ttraff.link'. The document body, though partially corrupted, contains text related to an 'Apple ipod shuffle manual 3rd generation' and the malicious URL, indicating a social engineering lure. The PDF also exhibits characteristics of a link farm, with numerous external links, suggesting an attempt to distribute malicious content or engage in SEO abuse.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=apple+ipod+shuffle+manual+3rd+generation
    • http://sarogobo.theparklinenc.com/uploads/1/3/1/4/131454065/javetifewovotazisi.pdf
    • http://files.whitepinesestate.com/uploads/1/3/1/3/131398452/3e4cc90d42.pdf
    • http://tosewaw.eventsforyou.net/uploads/1/3/1/6/131637306/3233535.pdf
    • http://files.sallyjcurtis.co.uk/uploads/1/3/2/7/132711954/1f44acbd5deb5.pdf
    • https://cdn.shopify.com/s/files/1/0461/9170/6263/files/ridazobopewaruvazivejo.pdf
    • https://cdn.shopify.com/s/files/1/0431/5650/4744/files/88648568996.pdf
    • https://cdn.shopify.com/s/files/1/0434/1966/4541/files/boundaries_in_dating_how_healthy_choices_grow_healthy_relationships.pdf
    • https://cdn.shopify.com/s/files/1/0429/2398/3015/files/intelligence_analytics_platforms.pdf
    • https://cdn.shopify.com/s/files/1/0427/6387/8566/files/aaliyah_one_in_a_million.pdf
    • https://cdn.shopify.com/s/files/1/0433/2149/1621/files/tevafamasimonobe.pdf
    • https://cdn.shopify.com/s/files/1/0431/5794/6522/files/lasaluwizekane.pdf
    • https://cdn.shopify.com/s/files/1/0430/6622/8898/files/linufuga.pdf
    • https://cdn.shopify.com/s/files/1/0434/3224/7457/files/11133793962.pdf
    • https://cdn.shopify.com/s/files/1/0443/1849/0780/files/ccna_file_download.pdf
    • https://cdn.shopify.com/s/files/1/0429/8955/1770/files/chidambaram_temple_bell_sound.pdf
    • https://cdn.shopify.com/s/files/1/0431/4647/7725/files/roper_chainsaw_manuals.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001392d.bin
5cecb76087aa797ab2f6cf4a614168b0a54b7ccd10cdfcc48ab970fe1ebeab16
pdf-font-stream PDF embedded font (sfnt) at offset 0x1392D 5608 bytes
font_01_sfnt_off00014c12.bin
a2140455302b8a2bce1551350a8d2fefabc30e0d79bf78fd9808bd8896a86ca8
pdf-font-stream PDF embedded font (sfnt) at offset 0x14C12 11604 bytes