Malicious PDF — malware analysis report

Static analysis result for SHA-256 fea70d5ffb70d370…

MALICIOUS

PDF

58.6 KB Created: 2020-09-04 23:25:41 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b16c48420c03eb6fa04145c7dcec8f18 SHA-1: d94b08b2b40329a823a56332fdb2ccfd6d42db20 SHA-256: fea70d5ffb70d37067ebc50b98cdd7eb79b261ac9c4a7c25703e81731f8b8b18
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a critical heuristic for containing a malicious redirector link, specifically 'https://ttraff.link/wix?keyword=broadsheet+article+layout'. Additionally, it exhibits characteristics of a PDF link farm, embedding numerous external PDF links, many hosted on shopify.com. The ML classifier also strongly indicated maliciousness. No scripts were extracted, but the sheer volume of embedded links suggests a campaign focused on driving traffic to potentially malicious or SEO-spam content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=broadsheet+article+layout
    • https://cdn.shopify.com/s/files/1/0434/2684/0738/files/moneyskill_answers_module_21.pdf
    • https://cdn.shopify.com/s/files/1/0428/0185/6668/files/pukilemojugafa.pdf
    • https://cdn.shopify.com/s/files/1/0436/3865/3086/files/bleacher_report_college_picks_week_3.pdf
    • https://cdn.shopify.com/s/files/1/0439/8841/8718/files/jakomudutagemidadaba.pdf
    • https://cdn.shopify.com/s/files/1/0427/5548/9948/files/adobe_garamond_premier_pro_font_free.pdf
    • https://cdn.shopify.com/s/files/1/0432/5956/0094/files/marketing_exam_questions_and_answers.pdf
    • https://cdn.shopify.com/s/files/1/0431/1102/2756/files/natal_birth_chart_report_free.pdf
    • https://cdn.shopify.com/s/files/1/0430/2965/9805/files/nazesixuk.pdf
    • https://cdn.shopify.com/s/files/1/0430/2841/4618/files/89012630984.pdf
    • https://static.usrfiles.com/ugd/5f4192_18e34f4c1f96414d8666fc38dff49b9d.pdf
    • https://static.usrfiles.com/ugd/8b9728_ff0c27a920b44dd3bee4bc5c89d71d56.pdf
    • https://cdn.shopify.com/s/files/1/0430/4211/1637/files/bullish_and_bearish_candlestick_patterns.pdf
    • https://cdn.shopify.com/s/files/1/0466/3934/9925/files/2013_mustang_gt_automatic_vs_manual.pdf
    • https://cdn.shopify.com/s/files/1/0436/1574/8253/files/madeon_the_city.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007d18.bin
33b154ca21fdc9fe10196dc2a036b6f502a37cfaadbc85f722410f8dc459a659
pdf-font-stream PDF embedded font (sfnt) at offset 0x7D18 7072 bytes
font_01_sfnt_off00009522.bin
6865323816bb0d907f749dbbcb38cb606d17f1b5eb1664d5cd2d3077d3aa7035
pdf-font-stream PDF embedded font (sfnt) at offset 0x9522 5180 bytes
font_02_sfnt_off0000a6b8.bin
16aca3cd6f195c103444e09948420df5ac15de83d96e08e2fa257f1a9e61a174
pdf-font-stream PDF embedded font (sfnt) at offset 0xA6B8 6968 bytes
font_03_sfnt_off0000b95c.bin
147f59bde65c125161dca5f2b51fd9298e425d8a65e71073462948416be4110e
pdf-font-stream PDF embedded font (sfnt) at offset 0xB95C 10436 bytes