Malicious PDF — malware analysis report

Static analysis result for SHA-256 30d8fc4a11639e22…

MALICIOUS

PDF

40.5 KB Created: 2020-08-31 08:53:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 99ba98383eed53dc536e601a0bf6508d SHA-1: 1bb7e283d680932e89fa1cf62ef845f6e754f8bd SHA-256: 30d8fc4a11639e2286bfac7e7d05965c0619571df2945c5253b203a499bddeb6
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.ru'. Additionally, it exhibits a PDF SEO link farm heuristic, indicating a large number of embedded links to other PDFs, with 'static.usrfiles.com' and 'cdn.shopify.com' being dominant hosts. The ML classifier also strongly flagged this PDF as malicious. The embedded document body text, though partially corrupted, contains the same suspicious URL and references to PDF files, reinforcing the link farm and redirection attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=wilson+reading+system+lesson+plan
    • https://static.usrfiles.com/ugd/cf14a4_02169202289c49478e7c0cd42e42b0a2.pdf
    • https://static.usrfiles.com/ugd/430cb2_31e79bcfe9294f56a088acb314ab2cda.pdf
    • https://static.usrfiles.com/ugd/b8c837_79014978337143ef8aa256f3ebac420b.pdf
    • https://static.usrfiles.com/ugd/b8c837_6573bfaeffc24253bee62bc962877ac2.pdf
    • https://cdn.shopify.com/s/files/1/0459/9349/2639/files/debit_card_expired_renewal_letter_format.pdf
    • https://cdn.shopify.com/s/files/1/0431/4890/2554/files/drawing_tutorial_manga.pdf
    • https://cdn.shopify.com/s/files/1/0435/9041/8591/files/nenavibokubiza.pdf
    • https://cdn.shopify.com/s/files/1/0431/7695/1974/files/cardiac_arrhythmias.pdf
    • https://cdn.shopify.com/s/files/1/0433/0097/8853/files/dilexavad.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000607d.bin
0f4d377ac474d99465cd323c63e1fcebd9b65c92a124c543043199639eb4132f
pdf-font-stream PDF embedded font (sfnt) at offset 0x607D 5392 bytes
font_01_sfnt_off000072c9.bin
6cded1c9398847cb2bda401b7f19cc2b1f68fc65e0edf702019c0a9e6c276258
pdf-font-stream PDF embedded font (sfnt) at offset 0x72C9 10192 bytes