Malicious PDF — malware analysis report

Static analysis result for SHA-256 1e20a21405d96b10…

MALICIOUS

PDF

52.4 KB Created: 2020-08-11 22:19:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 98c33825a0036ff81570c113d1cddff6 SHA-1: ba5bab85b1b92056da3579b8918ed0fb845cc647 SHA-256: 1e20a21405d96b106c66fa7e89d82436a8ed60417ebfc06df671ec9cb3ae21fd
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a high number of embedded links, many pointing to Shopify domains, suggesting a link farm or SEO poisoning tactic. One critical heuristic identified a link to a known malicious redirector at 'https://ttraff.ru/pify?keyword=pdf+capitalismo+y+esquizofrenia'. The document body, though heavily obfuscated, contains this URL and references 'wkhtmltopdf', indicating it was likely generated programmatically to host these links. The primary attack pattern is to lure users to the malicious redirector.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=pdf+capitalismo+y+esquizofrenia
    • http://gutatej.danielbuchanan.net/uploads/1/3/1/3/131384240/9e2d584c0ef.pdf
    • http://files.truevibrancy.com/uploads/1/3/1/3/131383838/9fa8ea965e.pdf
    • http://files.countryside-puppies.com/uploads/1/3/0/7/130740517/zezokanuke.pdf
    • http://files.ceblankenship.com/uploads/1/3/1/4/131406592/kuzixove-wafisipikag-duzapitod-sitaxowozesona.pdf
    • https://cdn.shopify.com/s/files/1/0429/5337/5897/files/diwavobarorakeju.pdf
    • https://cdn.shopify.com/s/files/1/0435/1849/2824/files/ladinanijusivufovawekiluj.pdf
    • https://cdn.shopify.com/s/files/1/0434/0698/3333/files/nusazefunigulawosevib.pdf
    • https://cdn.shopify.com/s/files/1/0428/8030/3270/files/nomujesajosubuwerurag.pdf
    • https://cdn.shopify.com/s/files/1/0429/8702/8639/files/canoscan_9000f_mark_ii_user_manual.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/fimovubonivunab.pdf
    • https://cdn.shopify.com/s/files/1/0431/6564/7012/files/stainless_steel_medieval_2.pdf
    • https://cdn.shopify.com/s/files/1/0429/9476/1877/files/zasaboje.pdf
    • https://cdn.shopify.com/s/files/1/0430/0098/7801/files/3268329328.pdf
    • https://cdn.shopify.com/s/files/1/0429/1903/5033/files/60757681726.pdf
    • https://cdn.shopify.com/s/files/1/0437/0199/3622/files/xepejira.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006abe.bin
ad57def553434b894ffff9680a2d6b30b9c2c265562724e99bb7cc2487a1f937
pdf-font-stream PDF embedded font (sfnt) at offset 0x6ABE 5460 bytes
font_01_sfnt_off00007d41.bin
99ffee9e58134979cb6dcb14d5f4126eac2297f121fbe02327e972f40b02e2e9
pdf-font-stream PDF embedded font (sfnt) at offset 0x7D41 10544 bytes
font_02_sfnt_off0000a121.bin
c94926d5202b085e184a5666363eda0a421a0de498e0fbda8ae973291059b9dc
pdf-font-stream PDF embedded font (sfnt) at offset 0xA121 16120 bytes
font_03_sfnt_off0000b60d.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0xB60D 4324 bytes