Malicious PDF — malware analysis report

Static analysis result for SHA-256 52b12a81a221cabd…

MALICIOUS

PDF

43.6 KB Created: 2020-08-30 13:56:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a843b05bb729ecf6a566089edb0d787d SHA-1: 6ad72adb2d5b4ede89635faec5cc0658ad5ff3b6 SHA-256: 52b12a81a221cabd90d4173a73ac7f474792e03a4293ee2db55ad3482a5d32fd
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link, pointing to a URL that appears to be part of a link farm designed for SEO manipulation. The document body, though heavily obfuscated, contains text related to 'acrobat pro dc serial number' and URLs that are likely part of this SEO spam campaign. The primary malicious URL identified is ttraff.com, which is known to host redirectors.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=acrobat+pro+dc+serial+number
    • https://cdn.shopify.com/s/files/1/0460/2632/6175/files/xupojiririlokidob.pdf
    • https://cdn.shopify.com/s/files/1/0431/5371/9452/files/sopalexoma.pdf
    • https://cdn.shopify.com/s/files/1/0432/2004/1886/files/dijetozadufawigawenu.pdf
    • https://static.usrfiles.com/ugd/b8c837_a3fad402974c48eda4ff995286b5a2a6.pdf
    • https://static.usrfiles.com/ugd/b8c837_fb081d87cd404d79988cd52e389d41e2.pdf
    • https://static.usrfiles.com/ugd/b8c837_0b3d776df8f4485c883bcef45308aea6.pdf
    • https://static.usrfiles.com/ugd/f84671_ce7ca4379f50452cab72a551f4cd2fab.pdf
    • https://static.usrfiles.com/ugd/b8c837_2f01ff7c3d394347bf32dd19df69c6b9.pdf
    • https://static.usrfiles.com/ugd/b8c837_810fe72510334c9dab066ae399dc5e42.pdf
    • https://static.usrfiles.com/ugd/b8c837_91be375e79674b619d94c44cb7b9ba1f.pdf
    • https://static.usrfiles.com/ugd/b8c837_9d68b757b6564f6597666d79b09c24aa.pdf
    • https://static.usrfiles.com/ugd/b8c837_67a5ee8dde504dfd8d09119a4d987df7.pdf
    • https://cdn.shopify.com/s/files/1/0437/1909/8523/files/utrack_online_gpx_track_report_generator.pdf
    • https://cdn.shopify.com/s/files/1/0440/2118/6718/files/beveloxawerofuku.pdf
    • https://cdn.shopify.com/s/files/1/0437/9397/3405/files/18507115735.pdf
    • https://cdn.shopify.com/s/files/1/0434/3444/2908/files/aldol_condensation_reaction_and_mechanism.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005dd2.bin
05f92546fd4753a1849b6152b05d3f87498d9145e21f3a21f25feda0ef3ef420
pdf-font-stream PDF embedded font (sfnt) at offset 0x5DD2 5232 bytes
font_01_sfnt_off00006f6f.bin
87f7ac8956f93d8cf28190ee844db5c010e6c6115530b774aea50c277b610044
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F6F 10988 bytes
font_02_sfnt_off00009351.bin
05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176
pdf-font-stream PDF embedded font (sfnt) at offset 0x9351 4324 bytes