Malicious PDF — malware analysis report

Static analysis result for SHA-256 f6b3ff47a5a2fce7…

MALICIOUS

PDF

44.5 KB Created: 2020-08-08 13:19:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: dc7a7248d678cc9bad5ab473fbde55b8 SHA-1: 5c0bec57b332e1a142dfa0cf91a7136b6fbbbc37 SHA-256: f6b3ff47a5a2fce733b9e4640a12f955726521592340159afcf17572e6a13c07
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a link to a known malicious redirector, ttraff.com, which is disguised as a beginner's guide to electric guitars. This redirector is part of a link farm, with many links pointing to benign Shopify URLs, likely for SEO manipulation. The ML classifier strongly flagged this PDF as malicious, indicating a high probability of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=electric+guitar+beginner+book+pdf
    • http://files.leonardoarriola.com/uploads/1/3/1/4/131438557/2032688.pdf
    • http://fanifuk.ricepaperdesigns.com/uploads/1/3/1/4/131438137/sewizuxonanu.pdf
    • http://files.aliciapettit.com/uploads/1/3/1/6/131637876/bapurekelubelovida.pdf
    • http://files.cpmyc.org/uploads/1/3/1/6/131606003/fb2d4772ed9.pdf
    • http://risovipul.stuccoriverside.com/uploads/1/3/0/8/130813765/8550052.pdf
    • https://cdn.shopify.com/s/files/1/0429/5376/9126/files/satiratabixetonefalizuj.pdf
    • https://cdn.shopify.com/s/files/1/0430/3188/8021/files/xijus.pdf
    • https://cdn.shopify.com/s/files/1/0429/1353/0019/files/4729032222.pdf
    • https://cdn.shopify.com/s/files/1/0430/3850/7169/files/31636519057.pdf
    • https://cdn.shopify.com/s/files/1/0434/5711/8374/files/az_100_dumps.pdf
    • https://cdn.shopify.com/s/files/1/0429/1795/3702/files/71334118862.pdf
    • https://cdn.shopify.com/s/files/1/0432/8531/5737/files/wafuluporaxomokidefemipak.pdf
    • https://cdn.shopify.com/s/files/1/0437/7139/6257/files/the_celestine_prophecy_full.pdf
    • https://cdn.shopify.com/s/files/1/0431/7832/8221/files/kagezukusirikozoduroxeli.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000061e5.bin
69865101dc388841de931e7d85454418a19adc25a80366287bb42fc5edd4c991
pdf-font-stream PDF embedded font (sfnt) at offset 0x61E5 5188 bytes
font_01_sfnt_off00007391.bin
30265de0469bc07768d0d6269a62a73b0ca7221c644f1f4890da715c4a0a97e3
pdf-font-stream PDF embedded font (sfnt) at offset 0x7391 10460 bytes
font_02_sfnt_off00009752.bin
1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361
pdf-font-stream PDF embedded font (sfnt) at offset 0x9752 4324 bytes