Malicious PDF — malware analysis report

Static analysis result for SHA-256 dfb7521f0c80e474…

MALICIOUS

PDF

80.0 KB Created: 2020-09-19 15:44:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f3434b3f9c58491db0a6fc8721e7b659 SHA-1: dfa6252799abc34e6f0b64044349102f6a55457f SHA-256: dfb7521f0c80e4742cac1505c274960941990935236faa4cbe753074fe5d1e47
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://ttraff.com/wix?keyword=tv+guide+madison+wi+53704'. This URL is embedded within the document's text, suggesting an attempt to trick the user into clicking it. The presence of numerous other benign-looking PDF links also indicates a link farm, a common tactic for SEO poisoning or distributing malicious content. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=tv+guide+madison+wi+53704
    • https://cdn.shopify.com/s/files/1/0429/9112/4643/files/aquifer_test_guidelines.pdf
    • https://cdn.shopify.com/s/files/1/0438/0839/1330/files/latest_bollywood_movies_2018_free_300mb.pdf
    • https://cdn.shopify.com/s/files/1/0434/1907/4712/files/sofagim.pdf
    • https://cdn.shopify.com/s/files/1/0437/8984/4637/files/befubojezumowegax.pdf
    • https://cdn.shopify.com/s/files/1/0465/5382/5430/files/dua_lipa_brit_awards_2018_performance.pdf
    • https://cdn.shopify.com/s/files/1/0438/4056/9501/files/89388930644.pdf
    • https://cdn.shopify.com/s/files/1/0435/8150/5695/files/buccal_route_of_drug_administration.pdf
    • https://60017b46-e098-4fba-a531-d3f29b99f30e.filesusr.com/ugd/112488_15039ae438724e72b849b7efc891a1f5.pdf?index=true
    • https://0cb612be-b762-412c-b29c-8bbfa175aa86.filesusr.com/ugd/738632_090af3e6e0024c16a1f63a26ab767fbd.pdf?index=true
    • https://cfe01e90-1d61-4adc-b483-7010f3a20bd3.filesusr.com/ugd/9f2514_0a31c3162e164bc2b468c7ff81501e20.pdf?index=true
    • https://9e79a79b-9c3d-405e-ac0a-fa02abd88fc4.filesusr.com/ugd/d1c05f_aead9f98e0f349978b1961acdba3d441.pdf?index=true
    • https://fded8412-78e7-4c39-bf82-453f95764885.filesusr.com/ugd/0779a3_d652f2b440ff4c6aa32103c9383011d1.pdf?index=true
    • https://4fe067b8-3064-4748-8f66-b333b7121d3e.filesusr.com/ugd/25c42e_a8e848debdb146869af231b2a24eaaf2.pdf?index=true
    • https://aeef23fd-dc1b-46e8-b354-692244a0e415.filesusr.com/ugd/a76634_34f1c3486bf64c93bac09ba3289993d9.pdf?index=true
    • https://14dabde4-6c2c-47b9-a50f-5e9fd283b548.filesusr.com/ugd/564d2e_98f840bca38b437eb9de6245929868b7.pdf?index=true
    • https://069e15db-421b-44d1-a9b5-3d2811035840.filesusr.com/ugd/451a43_90b6bee6ae5d4fc886a279e5b2a6d1d7.pdf?index=true
    • https://fb9ba1af-579a-4dc1-ae0b-df86eaa97e11.filesusr.com/ugd/d38238_8421e8c92e1043d98de9a03e2c39874f.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f8ce.bin
81b140d8571bc73350a6fd97b4c4f55e5a1ad130fd15b6cf5c0a52debccd3d7f
pdf-font-stream PDF embedded font (sfnt) at offset 0xF8CE 5716 bytes
font_01_sfnt_off00010c5d.bin
f2b6f5a5da165bb4a3a81fd922c1a12d34cc21b4e48d43a6fa4f9820cb523df5
pdf-font-stream PDF embedded font (sfnt) at offset 0x10C5D 10804 bytes