Malicious PDF — malware analysis report

Static analysis result for SHA-256 1ed09007aab1eeae…

MALICIOUS

PDF

44.8 KB Created: 2020-07-08 15:16:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bb4d929ad6bfa3fd8b5a193006ad2f8f SHA-1: 60ddb3a8cb9661513c696b4b2468eb2fad6c78c3 SHA-256: 1ed09007aab1eeae58bd5c2bd72fc016d30843a8f732ba7ec6c9029ce081dc07
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document was flagged by a machine learning classifier and contains numerous embedded links, indicating a malicious redirector or link farm. The primary URL, https://ttraff.ru/wb?keyword=sindrom%20horner%20adalah%20pdf, is identified as a malicious redirector. The document body contains garbled text along with the embedded URLs, suggesting it is designed to lure users into clicking malicious links rather than providing legitimate information.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wb?keyword=sindrom%20horner%20adalah%20pdf
    • http://files.medfieldheightspto.com/uploads/1/3/1/0/131070190/joridesaz.pdf
    • http://files.nelslehtinen.com/uploads/1/3/1/6/131606720/sizizijijabebigono.pdf
    • http://files.sapcrc.com/uploads/1/3/0/7/130775867/a49b304e84.pdf
    • http://files.tynksgemstonedesigns.com/uploads/1/3/2/7/132740415/7381d2f1749d4.pdf
    • http://files.otterworksusa.com/uploads/1/3/1/4/131437351/tasegus-rekafi-zeganusisaj-jigavulef.pdf
    • http://files.partnersforgrowthcb.com/uploads/1/3/1/3/131379290/batakijidifigif_rebalak.pdf
    • http://files.planninginblackandwhite.com/uploads/1/3/2/7/132710655/bobuzugipiz_renele_litazafurusagop.pdf
    • http://files.chickhillguideservice.com/uploads/1/3/0/7/130739658/pijajulikugisob_mubaxupakew_saguwizala_dizof.pdf
    • http://files.texashollandlops.com/uploads/1/3/1/3/131379371/7953459.pdf
    • https://jivevojenowe.files.wordpress.com/2020/07/xusuronematal.pdf
    • https://jakasizox.files.wordpress.com/2020/06/80515648881.pdf
    • https://xutawasekalo.files.wordpress.com/2020/07/72259051507.pdf
    • https://wikunakes.files.wordpress.com/2020/07/10157690045.pdf
    • https://pepavujewow.files.wordpress.com/2020/06/46725640179.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007309.bin
3ee0ae4f78bbf549de18ff132b300bd0ebde9973531004ebef2324f0adc1819d
pdf-font-stream PDF embedded font (sfnt) at offset 0x7309 4912 bytes
font_01_sfnt_off00008373.bin
59bf9b880870c8bf908988979369e0427cec9e9d8b855f2c2cda674c0abf1950
pdf-font-stream PDF embedded font (sfnt) at offset 0x8373 10392 bytes