Malicious PDF — malware analysis report

Static analysis result for SHA-256 3e0c18f22adb9dec…

MALICIOUS

PDF

34.4 KB Created: 2020-08-22 03:22:30 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a15ebb3b69ca36d70f1660f654eb9a7c SHA-1: f66ebb5a6970a3a4ee0e6fa45b6205100d580d9e SHA-256: 3e0c18f22adb9decf5139f6c080f63767fb58df2c0c23d7d0131cc83df169044
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, many of which point to external resources. One critical heuristic firing indicates that the PDF links to known malicious redirector infrastructure, specifically 'https://ttraff.ru/pify?keyword=amalina+full+song'. The document body contains garbled text but also includes the same URL, suggesting it is the primary lure. The presence of numerous Shopify-hosted PDF files, while some are marked benign, indicates a pattern of using these as part of a link farm to obscure the malicious redirector.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=amalina+full+song
    • http://files.eastgwentreferees.com/uploads/1/3/1/0/131070476/fdf38a3d3a.pdf
    • http://files.scripturefestival.org/uploads/1/3/2/6/132695530/tiwajuxotilu.pdf
    • http://files.deedeeraap.com/uploads/1/3/1/3/131398134/7daf69e15611ef.pdf
    • http://kofoxa.eastmen.eu/uploads/1/3/0/7/130738850/1608491.pdf
    • https://cdn.shopify.com/s/files/1/0431/7108/6485/files/89930216717.pdf
    • https://cdn.shopify.com/s/files/1/0429/5576/7967/files/zatiletamame.pdf
    • https://cdn.shopify.com/s/files/1/0444/8629/5719/files/buzegukuxaripefi.pdf
    • https://cdn.shopify.com/s/files/1/0431/9805/4558/files/saperupafivo.pdf
    • https://cdn.shopify.com/s/files/1/0429/7441/2949/files/wondershare_video_editor_free_for_pc.pdf
    • https://cdn.shopify.com/s/files/1/0432/7168/4252/files/1739399557.pdf
    • https://cdn.shopify.com/s/files/1/0433/7070/9150/files/mapa_mundi_sin_nombres_para_imprimir.pdf
    • https://cdn.shopify.com/s/files/1/0433/8424/2325/files/sobeveliregalubew.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004baa.bin
2e7ba82250300e68e40558d8c02b64cf05a3ad7f81473172abfa8891332c459f
pdf-font-stream PDF embedded font (sfnt) at offset 0x4BAA 4980 bytes
font_01_sfnt_off00005c8e.bin
ba5b465dd96c7dd4dbadba13c97c23d04c7c8656e60504a53b97e616a9bf4dcf
pdf-font-stream PDF embedded font (sfnt) at offset 0x5C8E 9656 bytes