Malicious PDF — malware analysis report

Static analysis result for SHA-256 4175b9f4068cf917…

MALICIOUS

PDF

91.3 KB Created: 2020-08-23 17:25:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9b88885a166b67e246d81c6134bc8642 SHA-1: d81259efbdee6c658b8c04b6daff2e3a17e4c817 SHA-256: 4175b9f4068cf9179d9c208886bb49fc1ca709381f5ec511d613058716238e81
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link to a known malicious redirector, ttraff.ru, which is disguised as a grammar PDF. This suggests a phishing or scam attempt to redirect the user to malicious content. The PDF also contains a large number of external links, many hosted on Shopify, which is characteristic of SEO link farm abuse to obscure malicious destinations. No scripts were extracted, but the primary malicious behavior is the redirection link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=afaan+oromo+grammar+pdf
    • http://files.davidhaltonart.com/uploads/1/3/1/4/131411281/2739380.pdf
    • http://files.theriversedgeranch.org/uploads/1/3/1/8/131871762/0f162.pdf
    • https://cdn.shopify.com/s/files/1/0431/8573/3792/files/50889640972.pdf
    • https://cdn.shopify.com/s/files/1/0433/7179/0486/files/95179403120.pdf
    • https://cdn.shopify.com/s/files/1/0431/0636/9703/files/25063582079.pdf
    • https://cdn.shopify.com/s/files/1/0438/6675/1131/files/jamixixolifotejogegexa.pdf
    • https://cdn.shopify.com/s/files/1/0431/2026/3322/files/vugigagobive.pdf
    • https://cdn.shopify.com/s/files/1/0427/8091/7926/files/21788160173.pdf
    • https://cdn.shopify.com/s/files/1/0433/7431/3621/files/cmara_de_comercio_internacional_cci.pdf
    • https://cdn.shopify.com/s/files/1/0434/2507/1256/files/69312847966.pdf
    • https://cdn.shopify.com/s/files/1/0432/9373/7118/files/fuguludat.pdf
    • https://cdn.shopify.com/s/files/1/0436/8911/5801/files/10710715494.pdf
    • https://cdn.shopify.com/s/files/1/0429/6327/1833/files/vekozuzed.pdf
    • https://cdn.shopify.com/s/files/1/0440/5490/4997/files/181793581.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e3c9.bin
7a9594093a3e35b8075b0781b510b8a7ff73aebc078304f8046491dab833f459
pdf-font-stream PDF embedded font (sfnt) at offset 0xE3C9 7160 bytes
font_01_sfnt_off0000f5e9.bin
bcb9a7bafcab8ae10bed124e18239796db26ae9c41967fcb743a15f315e8f9c4
pdf-font-stream PDF embedded font (sfnt) at offset 0xF5E9 5140 bytes
font_02_sfnt_off0001074b.bin
1981be102a55c29e41e4993dd36ede6063b468a10ee11872ca1b35e2506394a5
pdf-font-stream PDF embedded font (sfnt) at offset 0x1074B 3056 bytes
font_03_sfnt_off00011420.bin
9ef291cbbdf7cafce0c0c85782e1470a96f2d1639f920fe2e224a1bb7b3afe50
pdf-font-stream PDF embedded font (sfnt) at offset 0x11420 17224 bytes
font_04_sfnt_off0001480e.bin
c4facf4bacf803e82b286e70f27fc1ec62b68736093825893ad1c7328c9fc562
pdf-font-stream PDF embedded font (sfnt) at offset 0x1480E 16176 bytes