Malicious PDF — malware analysis report

Static analysis result for SHA-256 45bfc68c6370e792…

MALICIOUS

PDF

41.3 KB Created: 2020-08-01 15:11:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b4ede8afa43af04472da4091a28925ed SHA-1: 5f57684f816a919d1c334bb658e3d45e9217eb12 SHA-256: 45bfc68c6370e792e82e3586880b21a694d70dfd490d583ed54d7ca6b3b9804b
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a link to a known malicious redirector, ttraff.ru, disguised with a search query for a service manual. The document body, though heavily obfuscated, contains the same lure text and the malicious URL. The PDF also exhibits characteristics of a link farm, with numerous embedded links to other PDFs, likely for SEO poisoning or to spread malicious content across multiple domains. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=mahindra+tractor+service+manual+pdf
    • http://files.pinwellbooks.co.uk/uploads/1/3/0/7/130775357/tukabolu_nifadisogujufa_rujeku_wuzuzovuzifixob.pdf
    • http://files.nancychartierstudios.com/uploads/1/3/1/4/131437285/b692ede.pdf
    • http://files.dglivestock.com/uploads/1/3/0/7/130776503/jorix.pdf
    • http://files.poomah.com/uploads/1/3/2/6/132681885/6956639.pdf
    • https://cdn.shopify.com/s/files/1/0435/2458/7674/files/dobajewozisubav.pdf
    • https://cdn.shopify.com/s/files/1/0431/7744/3483/files/zalimojalut.pdf
    • https://cdn.shopify.com/s/files/1/0429/6107/6387/files/24659823954.pdf
    • https://cdn.shopify.com/s/files/1/0434/0727/8238/files/maker_genome_annotation.pdf
    • https://cdn.shopify.com/s/files/1/0432/0837/6482/files/velijuzafa.pdf
    • https://cdn.shopify.com/s/files/1/0429/2801/3475/files/sodudakasijixeke.pdf
    • https://cdn.shopify.com/s/files/1/0430/9132/9173/files/xexirujem.pdf
    • https://cdn.shopify.com/s/files/1/0429/1415/2607/files/soxaranoxaxotamerav.pdf
    • https://cdn.shopify.com/s/files/1/0431/9238/5700/files/gufaleranugakuresofan.pdf
    • https://cdn.shopify.com/s/files/1/0434/7743/4525/files/sabakof.pdf
    • https://cdn.shopify.com/s/files/1/0427/6004/4710/files/lodemawe.pdf
    • https://cdn.shopify.com/s/files/1/0433/7300/2902/files/nesigifixemu.pdf
    • https://cdn.shopify.com/s/files/1/0433/2408/0282/files/zelolodosoxa.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000062a6.bin
337f45a280c61c89e83c0b5600f3b189d26a58ee1617050ed5eaa6d38aa4de3f
pdf-font-stream PDF embedded font (sfnt) at offset 0x62A6 5460 bytes
font_01_sfnt_off00007520.bin
f03acd8804f1dac9ea199b0e9ea95a9c34781b41c95513b001998053d219e9fe
pdf-font-stream PDF embedded font (sfnt) at offset 0x7520 10420 bytes