Malicious PDF — malware analysis report

Static analysis result for SHA-256 247e99c41868f341…

MALICIOUS

PDF

42.0 KB Created: 2020-08-22 00:25:42 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 16db50d8ef4167f910e9091939253ff3 SHA-1: fd11d3ae55131b6bf98e1e6af2db516ee8a8656d SHA-256: 247e99c41868f3411794bb3c047ae485272f276a5d410b5f644ce17c73a6cee9
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF was flagged as malicious due to a critical heuristic identifying it as a link farm pointing to known malicious redirector infrastructure. The document body contains a URL that leads to 'ttraff.ru', which is associated with malicious redirects. The presence of numerous external PDF links, many hosted on Shopify, suggests an attempt to obscure the final malicious destination or to generate traffic through a link farm. No scripts were extracted, and the document body itself is largely unreadable binary data with some embedded URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=pyramid+solitaire+game+free++for+pc
    • http://files.amaniabraham.com/uploads/1/3/0/9/130969235/kejager.pdf
    • http://files.kmphotographyma.com/uploads/1/3/1/4/131407165/1126974.pdf
    • http://ginigomi.emmatomlinsonmusic.com/uploads/1/3/0/8/130874474/vefarijowes-bibox-nonab-rawadema.pdf
    • http://tebuw.grapesociety.org/uploads/1/3/2/6/132683001/moxafuzubirejed.pdf
    • http://mopiv.celst.org.uk/uploads/1/3/0/8/130874019/xabedirim.pdf
    • https://cdn.shopify.com/s/files/1/0436/1850/0765/files/68115361243.pdf
    • https://cdn.shopify.com/s/files/1/0430/5564/4823/files/browser_code_language.pdf
    • https://cdn.shopify.com/s/files/1/0432/6513/0658/files/panchatantra_stories_in_telugu.pdf
    • https://cdn.shopify.com/s/files/1/0433/5576/6942/files/como_instalar_un_calentador_solar.pdf
    • https://cdn.shopify.com/s/files/1/0431/3851/5095/files/19883364740.pdf
    • https://cdn.shopify.com/s/files/1/0438/4745/0789/files/jofenarajonited.pdf
    • https://cdn.shopify.com/s/files/1/0433/3345/1944/files/76596774340.pdf
    • https://cdn.shopify.com/s/files/1/0434/2729/9478/files/jinulovexiki.pdf
    • https://cdn.shopify.com/s/files/1/0430/7333/9559/files/lidojakijidido.pdf
    • https://cdn.shopify.com/s/files/1/0430/7854/9665/files/skew_hermitian_matrix_example.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/20424522606.pdf
    • https://cdn.shopify.com/s/files/1/0438/2805/2130/files/55815286774.pdf
    • https://cdn.shopify.com/s/files/1/0437/1460/9303/files/titukateguru.pdf
    • https://cdn.shopify.com/s/files/1/0427/5427/7532/files/bawiwolun.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000063e5.bin
2c28cbac4746de891e43cf600ed158a3eac0973deb3f9ed3339286e636b4e360
pdf-font-stream PDF embedded font (sfnt) at offset 0x63E5 5576 bytes
font_01_sfnt_off000076ce.bin
d429a0d833d1dcc1c46d018b55f829c45e4aca167fac6ba445903f68ac7e8134
pdf-font-stream PDF embedded font (sfnt) at offset 0x76CE 10604 bytes