Malicious PDF — malware analysis report

Static analysis result for SHA-256 50be0aeb59bf71f8…

MALICIOUS

PDF

60.0 KB Created: 2020-09-01 15:01:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ce59ded03642e73ae615fb8a3c15f1da SHA-1: 3816a0efb0f391fc1b8b25c6402496e469e4bffa SHA-256: 50be0aeb59bf71f84320907b34ae322093b08319421316c41d0ba0efa1f18469
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link pointing to 'ttraff.ru', which is also listed as an IOC. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded URLs, many hosted on Shopify. The ML classifier strongly indicated maliciousness. The document body, though heavily obfuscated, contains the malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=konsep+liberalisme+pdf
    • https://cdn.shopify.com/s/files/1/0431/1102/2756/files/medotosunedelubob.pdf
    • https://cdn.shopify.com/s/files/1/0433/3341/9166/files/spider_body_parts.pdf
    • https://cdn.shopify.com/s/files/1/0432/6418/0390/files/33783060623.pdf
    • https://static.usrfiles.com/ugd/696117_c376c1e6f3844ad0aa31055eaf8a5862.pdf
    • https://cdn.shopify.com/s/files/1/0434/7327/2998/files/taxalikonavowekarir.pdf
    • https://cdn.shopify.com/s/files/1/0437/0671/2219/files/remumigazumetilu.pdf
    • https://cdn.shopify.com/s/files/1/0429/2775/1321/files/nesuvimuverevibo.pdf
    • https://cdn.shopify.com/s/files/1/0429/9948/0473/files/60383468977.pdf
    • https://static.usrfiles.com/ugd/2ac701_eadd5726fb6f44a3821a8a69c0f36b69.pdf
    • https://static.usrfiles.com/ugd/5be868_908be43246534f888e39c4ab1d92d3e6.pdf
    • https://static.usrfiles.com/ugd/f46427_dc0c155feb654e9eb6b923f58479b024.pdf
    • https://static.usrfiles.com/ugd/2f3ac6_347cb58fe21e41a3a90b9e0c08120db4.pdf
    • https://static.usrfiles.com/ugd/b8c837_6919ffb555e6458f9eca6a2dadef92d9.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ad49.bin
ccdb7ec7aa384f7b24866b0de1b9d30c595c6d08e54266a9a5073236145b868a
pdf-font-stream PDF embedded font (sfnt) at offset 0xAD49 5296 bytes
font_01_sfnt_off0000bf2f.bin
b7e6b0cd23a461584559b93efea0b58c8ba25e8205f7f62fcf30877e4ae9721c
pdf-font-stream PDF embedded font (sfnt) at offset 0xBF2F 10496 bytes