Malicious PDF — malware analysis report

Static analysis result for SHA-256 ea50e0872095eaf3…

MALICIOUS

PDF

47.3 KB Created: 2020-08-02 20:08:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a16b6d68bcb577c0ad5da0c84629d9cd SHA-1: e428b9e0a856cfb2f5cc88f804e146fd72e53501 SHA-256: ea50e0872095eaf3684deb8ccdab3027521aeb802b642deb6e02d0f3c8c8e79f
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.cc'. Additionally, it exhibits characteristics of a PDF link farm, with numerous external links, many hosted on Shopify. The ML classifier strongly supports the malicious verdict. The document body text is largely unreadable binary data, but the embedded URL 'https://ttraff.cc/pify?keyword=readonly+option+is+set+add+to+override' is clearly visible and is the primary indicator of malicious intent, likely serving as a lure or redirector to further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=readonly+option+is+set+add+to+override
    • http://files.srobinsonphoto.com/uploads/1/3/1/3/131380436/pimewevefaviliv.pdf
    • http://files.stthomastheapostleparishmontfortwi.com/uploads/1/3/1/8/131856232/tutexojut.pdf
    • http://files.bibletruthmagazine.com/uploads/1/3/0/8/130874478/rodunanudujepe-lutife.pdf
    • http://files.kelownanaturopathicdoctor.ca/uploads/1/3/1/0/131070152/wutomifeligenixorod.pdf
    • https://cdn.shopify.com/s/files/1/0432/4796/0232/files/27771170812.pdf
    • https://cdn.shopify.com/s/files/1/0431/6217/3602/files/rukewututanozefapinezej.pdf
    • https://cdn.shopify.com/s/files/1/0431/1551/1968/files/9315230180.pdf
    • https://cdn.shopify.com/s/files/1/0436/8865/7049/files/lalijalagaketewumedodif.pdf
    • https://cdn.shopify.com/s/files/1/0431/9975/8497/files/lapirarerifedazef.pdf
    • https://cdn.shopify.com/s/files/1/0429/1959/2103/files/74897867046.pdf
    • https://cdn.shopify.com/s/files/1/0433/7080/7459/files/4151248667.pdf
    • https://cdn.shopify.com/s/files/1/0432/0778/6657/files/19626913766.pdf
    • https://cdn.shopify.com/s/files/1/0429/7146/3831/files/datuxozoguwixasodumek.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/53567737566.pdf
    • https://cdn.shopify.com/s/files/1/0433/0808/9509/files/39759687233.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005a6c.bin
75dc98287c68d03b27a5afbb380221304c98b046a36dc92a249eb6bdce42e8fb
pdf-font-stream PDF embedded font (sfnt) at offset 0x5A6C 5944 bytes
font_01_sfnt_off00006ead.bin
71e6af33f218dcc3b0d87cdd450e5db7ab6059380554815e8ba0f1a687e860d9
pdf-font-stream PDF embedded font (sfnt) at offset 0x6EAD 5124 bytes
font_02_sfnt_off00008038.bin
13cc7351a7a73c836116f1ebb291deb7fe1738246cf6d648a045e63bfef63cc2
pdf-font-stream PDF embedded font (sfnt) at offset 0x8038 14576 bytes