Malicious PDF — malware analysis report

Static analysis result for SHA-256 2a66b6160cb615bc…

MALICIOUS

PDF

42.9 KB Created: 2020-08-07 09:33:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2e2ae78da92e5b8dedc1efbe84b3dfdc SHA-1: 634450d02da72986b481ff14b85adaae971288a7 SHA-256: 2a66b6160cb615bc3afeb2aa5432924d9574761a9f0bb3d5f366c704892b6257
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a high number of external links, many pointing to Shopify domains, suggesting a link farm or SEO poisoning attempt. The primary malicious indicator is the redirector link to 'ttraff.ru', which is known malicious infrastructure. The document body itself is heavily obfuscated and contains embedded URLs, reinforcing the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=the+asch+effect+a+child+of+its+time+pdf
    • http://files.1550art.com/uploads/1/3/2/7/132740214/mufudimokoxe_binosejiga_voxujajawubaj.pdf
    • http://files.elginparkathletics.com/uploads/1/3/1/4/131406413/xikudenaw.pdf
    • http://files.krumbsnatcherenterprises.com/uploads/1/3/1/4/131483719/lerif.pdf
    • http://files.uvcoolme.com/uploads/1/3/1/4/131407299/tujugireguroxa_nabiw_dejor_kobumavoko.pdf
    • http://files.suzanneahmet.com/uploads/1/3/0/9/130969045/zubigavilanexejo.pdf
    • https://cdn.shopify.com/s/files/1/0433/9315/5230/files/32734842309.pdf
    • https://cdn.shopify.com/s/files/1/0432/9763/6512/files/tameporufasevibexe.pdf
    • https://cdn.shopify.com/s/files/1/0433/3862/9270/files/71767596988.pdf
    • https://cdn.shopify.com/s/files/1/0432/0047/9391/files/81797568114.pdf
    • https://cdn.shopify.com/s/files/1/0430/4653/5322/files/letubefepetagumefije.pdf
    • https://cdn.shopify.com/s/files/1/0433/4927/8875/files/physical_therapy_for_down_syndrome.pdf
    • https://cdn.shopify.com/s/files/1/0433/0792/5654/files/postman_api_testing_tutorial.pdf
    • https://cdn.shopify.com/s/files/1/0431/6033/8586/files/lokivomoxot.pdf
    • https://cdn.shopify.com/s/files/1/0431/7092/2652/files/70122986681.pdf
    • https://cdn.shopify.com/s/files/1/0435/9297/4499/files/jazz_piano_music_theory.pdf
    • https://cdn.shopify.com/s/files/1/0436/8757/5705/files/53009569312.pdf
    • https://cdn.shopify.com/s/files/1/0448/4051/7792/files/wotlk_prot_paladin.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006987.bin
1b1fdf89b44223a830dc9e5974addf69ff4c0aa66fa356ad02ae4aada8c6ab7b
pdf-font-stream PDF embedded font (sfnt) at offset 0x6987 5248 bytes
font_01_sfnt_off00007b3a.bin
d0aff235477560bea3e3746b67c81fd7da28312427de92c57c459771fb772a51
pdf-font-stream PDF embedded font (sfnt) at offset 0x7B3A 10400 bytes