Malicious PDF — malware analysis report

Static analysis result for SHA-256 58795f512b6de3b2…

MALICIOUS

PDF

43.6 KB Created: 2020-08-19 07:49:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a402bf111525f7dedbd6d0c259c9906f SHA-1: 7b41767842c13460154596eb8b333298af8b86fa SHA-256: 58795f512b6de3b20b9ede2a5eaf281b32a1532bea7937fecc906a445e9737b5
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to ttraff.com. The document body, though heavily obfuscated, contains text fragments related to 'Acrobat professional' and a URL, suggesting a lure. The presence of numerous external PDF links, many hosted on Shopify, further indicates a link farm strategy, likely to obscure the ultimate malicious destination.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=acrobat+professional+11.+0+mlp+aoo+full
    • http://files.hillarydimenna.com/uploads/1/3/0/7/130739308/kawegotu.pdf
    • http://doxuzumat.westendprimaryschool.co.uk/uploads/1/3/1/6/131636664/guxevolujob-sutuw-madip-xisifuzesegib.pdf
    • http://files.artbyjj.co.uk/uploads/1/3/0/7/130740624/823b583bf2.pdf
    • https://cdn.shopify.com/s/files/1/0443/8881/0918/files/ana_catalina_emmerick_libros_gratis.pdf
    • https://cdn.shopify.com/s/files/1/0430/7920/5031/files/97768732717.pdf
    • https://cdn.shopify.com/s/files/1/0434/7409/2196/files/1049588761.pdf
    • https://cdn.shopify.com/s/files/1/0434/7310/9152/files/dekezizaxokodag.pdf
    • https://cdn.shopify.com/s/files/1/0434/3093/6733/files/70928262469.pdf
    • https://cdn.shopify.com/s/files/1/0433/7709/8902/files/52050861645.pdf
    • https://cdn.shopify.com/s/files/1/0438/2228/4960/files/getigumizegepa.pdf
    • https://cdn.shopify.com/s/files/1/0434/5203/9328/files/75215054720.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/kofuka.pdf
    • https://cdn.shopify.com/s/files/1/0437/2656/9633/files/slope_stability_design.pdf
    • https://cdn.shopify.com/s/files/1/0434/6583/4658/files/45873211908.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006370.bin
b1b7050471534b1ec836a84d60b81d0bb0b585fe26f34f4af9facce0d81e4716
pdf-font-stream PDF embedded font (sfnt) at offset 0x6370 5516 bytes
font_01_sfnt_off0000761a.bin
1654c4beac132290b1f0a50a542eff264f552fec8c3f49a1f7caff05b30bef6f
pdf-font-stream PDF embedded font (sfnt) at offset 0x761A 13668 bytes