Malicious PDF — malware analysis report

Static analysis result for SHA-256 2d6d9285a58e3bc6…

MALICIOUS

PDF

59.1 KB Created: 2020-08-04 07:20:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 96d3e82ca749deac04f986c59dc8c643 SHA-1: 6406c491f8f61add5f0ba4abd7620f2f9aa7cdda SHA-256: 2d6d9285a58e3bc6512dcf72bf617bb7ba650aca61c4d0bc19a52a6f7386f3e2
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document was flagged by multiple critical heuristics for containing malicious redirector links and a large number of external PDF links, suggesting a link farm or SEO manipulation tactic. The primary malicious URL identified is https://ttraff.ru/pify?keyword=anopheles+funestus+pdf. While the document body contains garbled text, the presence of numerous links points towards a malicious intent to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=anopheles+funestus+pdf
    • http://files.stitchedwithcare.com/uploads/1/3/1/3/131383624/dowumi-wefudazebukop-wivavin-tajewowe.pdf
    • http://files.jvgardens.com/uploads/1/3/1/3/131383384/bodegifuvetitimijeb.pdf
    • http://files.patsysbarandgrill.com/uploads/1/3/1/1/131163772/12f05.pdf
    • https://cdn.shopify.com/s/files/1/0432/6129/6790/files/photoshop_cs6_crack.pdf
    • https://cdn.shopify.com/s/files/1/0431/4651/0487/files/61781559113.pdf
    • https://cdn.shopify.com/s/files/1/0432/2538/3073/files/mozojemetobabesozukate.pdf
    • https://cdn.shopify.com/s/files/1/0427/8039/3639/files/fetubozavakidekatoxupoz.pdf
    • https://cdn.shopify.com/s/files/1/0432/0421/4942/files/7908184976.pdf
    • https://cdn.shopify.com/s/files/1/0430/9896/4117/files/setup_local_host.pdf
    • https://cdn.shopify.com/s/files/1/0433/3764/6245/files/35844489142.pdf
    • https://cdn.shopify.com/s/files/1/0433/8129/3221/files/donuxolutogopigazedol.pdf
    • https://cdn.shopify.com/s/files/1/0432/1420/9186/files/20558438821.pdf
    • https://cdn.shopify.com/s/files/1/0435/1626/4616/files/85120544867.pdf
    • https://cdn.shopify.com/s/files/1/0431/2629/2634/files/98390667327.pdf
    • https://cdn.shopify.com/s/files/1/0432/3885/0728/files/jobulufavovotupax.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com/s

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000075df.bin
ef89344cb56e066dd2b8d40f5ede2ee7ca8375a0bbc828ee97e527adc05ba8b1
pdf-font-stream PDF embedded font (sfnt) at offset 0x75DF 4812 bytes
font_01_sfnt_off0000863f.bin
d0c9e33916e9e64e42e31bcf0d345f6c2fcd41735b1a34df0119bd0eb1094281
pdf-font-stream PDF embedded font (sfnt) at offset 0x863F 3720 bytes
font_02_sfnt_off000091a3.bin
e69a7e2639685bfec698cb28dd15263a3b9cda6d4763169966d5dc0a98310046
pdf-font-stream PDF embedded font (sfnt) at offset 0x91A3 16120 bytes
font_03_sfnt_off0000c3a4.bin
afc74f38843c731570a39f43dbbf9b2421615f86d5200419a129b4bb30d3e78b
pdf-font-stream PDF embedded font (sfnt) at offset 0xC3A4 7928 bytes