Malicious PDF — malware analysis report

Static analysis result for SHA-256 574908611baeed7b…

MALICIOUS

PDF

42.5 KB Created: 2020-08-10 19:22:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 976d02d78fcbe7f4898b22597d44c6cd SHA-1: a186954f12efad71f965920b2c966af3a3f90c23 SHA-256: 574908611baeed7b334ca4f6d8a0d5ee62efe7220a5cdbc5592f10c5bfae0e6f
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains numerous embedded links, including one pointing to a known malicious redirector at 'https://ttraff.ru/pify?keyword=famous+books+in+english+literature+pdf+free+download'. This suggests a social engineering attack aiming to redirect users to malicious content. The presence of a link farm heuristic further supports this, indicating an attempt to manipulate search engine results or distribute links broadly. No scripts were extracted, but the PDF structure and embedded URLs are sufficient to infer the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=famous+books+in+english+literature+pdf+free+download
    • http://files.comedyblockpartyent.com/uploads/1/3/0/8/130814065/2d9f84759.pdf
    • http://xuwitoror.nikhilchari.com/uploads/1/3/2/6/132682137/6146515.pdf
    • http://files.maldonarchive.com/uploads/1/3/2/6/132682655/rumejawezubi_kexosejeg_tatekaki_fuvapemalotux.pdf
    • https://cdn.shopify.com/s/files/1/0429/3564/8409/files/71740652259.pdf
    • https://cdn.shopify.com/s/files/1/0432/6316/4580/files/peer_assessment_in_education.pdf
    • https://cdn.shopify.com/s/files/1/0433/0681/1560/files/41609326033.pdf
    • https://cdn.shopify.com/s/files/1/0431/8281/7441/files/arnold_blueprint_to_cuts_phase_2.pdf
    • https://cdn.shopify.com/s/files/1/0438/1717/3149/files/participatory_action_research.pdf
    • https://cdn.shopify.com/s/files/1/0432/7161/8723/files/52638059676.pdf
    • https://cdn.shopify.com/s/files/1/0430/8838/0061/files/44017975434.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/55628578329.pdf
    • https://cdn.shopify.com/s/files/1/0436/1843/5229/files/geometrical_optics_lecture_notes.pdf
    • https://cdn.shopify.com/s/files/1/0429/5802/8959/files/38872129028.pdf
    • https://cdn.shopify.com/s/files/1/0430/7497/7945/files/33386647592.pdf
    • https://cdn.shopify.com/s/files/1/0433/2797/9678/files/therapist_guide_to_clinical_intervention.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006701.bin
7e8ea6a65571533cce352ca8a7097af680200049a62968ec942bd29628017ad5
pdf-font-stream PDF embedded font (sfnt) at offset 0x6701 5704 bytes
font_01_sfnt_off00007a4e.bin
d40f0235df592e23348b27e8e759c1b0e190e97d9d9fae7ea399318c51f21e85
pdf-font-stream PDF embedded font (sfnt) at offset 0x7A4E 10120 bytes