Malicious PDF — malware analysis report

Static analysis result for SHA-256 e706bdb563470bfb…

MALICIOUS

PDF

47.4 KB Created: 2020-09-01 05:11:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1b2136bcda025b71013aac8b05c032eb SHA-1: 4add7597ccbcfd6a352bbd7fa9f82e7ec9b7adbe SHA-256: e706bdb563470bfbc5cafaf569835ce2b2d70fa7d8de0b9ebc3c3cff6c6999eb
152 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.002 Spearphishing Attachment

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. Additionally, another critical heuristic indicates a PDF link farm, suggesting an attempt to manipulate search engine results or distribute multiple malicious links. The ML classifier also strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains the same malicious URL, reinforcing the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=add+audio+to+video+online+free
    • https://static.usrfiles.com/ugd/b8c837_c4a69e558cd047b590be4310bba8b367.pdf
    • https://static.usrfiles.com/ugd/b8c837_20e39a787be1497a9b1ff2e3c267bea5.pdf
    • https://static.usrfiles.com/ugd/8d0191_d9489712fd864467a087bd9b147199b3.pdf
    • https://static.usrfiles.com/ugd/3de8a6_986cd88ba1f04df497cd343df7e4a085.pdf
    • https://static.usrfiles.com/ugd/b4a829_631cfe0489474f79a97184b1930c0547.pdf
    • https://static.usrfiles.com/ugd/fb83f1_7230bb564a5846ae9e1180e78b047ead.pdf
    • https://static.usrfiles.com/ugd/2b3f46_8fc9a310a0764136bf63d8a99eb62383.pdf
    • https://static.usrfiles.com/ugd/921909_0d6df1be6d664a3cb1b1c4dd67e1a698.pdf
    • https://static.usrfiles.com/ugd/b8c837_39819be299b749e4a93c58badf226a85.pdf
    • https://static.usrfiles.com/ugd/b8c837_6b8d4db34fb94d73a78dfc389e551d89.pdf
    • https://static.usrfiles.com/ugd/c618e9_527c4facc3ca4d4fbae0d6cb7d441a7c.pdf
    • https://static.usrfiles.com/ugd/5926b4_0560ecab98b343fca27f0904fe1f62f1.pdf
    • https://static.usrfiles.com/ugd/db93e9_9c8b027bd1f84ea4bad2b1a8318e7698.pdf
    • https://static.usrfiles.com/ugd/c068f8_d7520036d22748c285dd84bc6737964e.pdf
    • https://cdn.shopify.com/s/files/1/0461/9164/0739/files/mumajefogunudabuli.pdf
    • https://cdn.shopify.com/s/files/1/0437/0608/9640/files/windows_98_se_product_key.pdf
    • https://cdn.shopify.com/s/files/1/0434/7196/2265/files/46714049501.pdf
    • https://cdn.shopify.com/s/files/1/0440/3098/4357/files/atomic_structure_answers.pdf
    • https://cdn.shopify.com/s/files/1/0428/9354/1535/files/buvawupadebatozi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006f69.bin
d5bd35084efd855cccf66a532554a3a6f767a9427d37147315700828951f32e4
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F69 4652 bytes
font_01_sfnt_off00007f44.bin
9962bec245ed97e1d56924a0403667114efe22b1475fccb9035d3863634e6d35
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F44 10276 bytes
font_02_sfnt_off0000a223.bin
05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176
pdf-font-stream PDF embedded font (sfnt) at offset 0xA223 4324 bytes