Malicious PDF — malware analysis report

Static analysis result for SHA-256 f3338e33be6cfd58…

MALICIOUS

PDF

39.6 KB Created: 2020-08-17 07:30:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e2fc8cd0f68c5e286d1d0a16a979e362 SHA-1: cced068e12c74ebff217b3d38c5af33d583393be SHA-256: f3338e33be6cfd58df081a735478de8ab24761c72e8de7169291a35154800e68
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link to a known malicious redirector, ttraff.cc, which is disguised as a sociology question paper. The document also hosts a large number of external PDF links, many pointing to Shopify domains, likely as part of an SEO spam campaign to improve search engine ranking for malicious content. The ML classifier strongly indicated maliciousness, and the overall structure suggests a phishing or redirection attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=bpsc+sociology+optional+question+paper+pdf
    • http://files.inharmonyliving.org/uploads/1/3/0/7/130739783/gasabol.pdf
    • http://files.pamsteashoppe.com/uploads/1/3/1/3/131384789/59b03f6f49c09c.pdf
    • http://files.lucyhall-photography.com/uploads/1/3/0/7/130739366/83d733c6f7223.pdf
    • https://cdn.shopify.com/s/files/1/0433/5344/0414/files/yaseen_sharif_in_english.pdf
    • https://cdn.shopify.com/s/files/1/0429/6350/1222/files/13907205553.pdf
    • https://cdn.shopify.com/s/files/1/0431/3251/8554/files/jepalabolidotusiro.pdf
    • https://cdn.shopify.com/s/files/1/0438/3604/7522/files/wovege.pdf
    • https://cdn.shopify.com/s/files/1/0431/6561/4234/files/9712064369.pdf
    • https://cdn.shopify.com/s/files/1/0428/7778/0134/files/animal_welfare_act.pdf
    • https://cdn.shopify.com/s/files/1/0431/8894/5045/files/89998014359.pdf
    • https://cdn.shopify.com/s/files/1/0435/4719/7594/files/tobepumuval.pdf
    • https://cdn.shopify.com/s/files/1/0434/1720/6949/files/luranigaperamusizedubo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004508.bin
0b8639594291194d82ee306eb411c73c0a3ae2a67ee991966cada05c8b034276
pdf-font-stream PDF embedded font (sfnt) at offset 0x4508 5600 bytes
font_01_sfnt_off00005818.bin
ef418dd3d94e0143379bb0e8bf7aac8c0edfc9082313b84a8766b20974fddd3f
pdf-font-stream PDF embedded font (sfnt) at offset 0x5818 9512 bytes
font_02_sfnt_off000078de.bin
89417c7036de7039bdbd6d965fd3bd70782272e1b4d9c16d55ba4ceeb2cf20af
pdf-font-stream PDF embedded font (sfnt) at offset 0x78DE 7160 bytes