Malicious PDF — malware analysis report

Static analysis result for SHA-256 7ba1ef104c4d5351…

MALICIOUS

PDF

86.9 KB Created: 2020-09-07 03:49:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 979333eb4b6df5192b192f629e05267e SHA-1: 162d5bc606a01a655e2808a4dd9702b766d44982 SHA-256: 7ba1ef104c4d535178b2900413bf7342c2a9b06315b9e0e7fbd6e136646cd71e
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged as malicious by an ML classifier and contains a critical heuristic indicating it links to known malicious redirector infrastructure. It also exhibits characteristics of a PDF link farm, with numerous external links. The embedded URL 'https://ttraff.me/wix?keyword=html+website+templates+for+business' is the primary indicator of malicious intent, likely serving as a lure or redirector to a phishing or malware distribution site.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=html+website+templates+for+business
    • https://static.usrfiles.com/ugd/e02969_ea0f9b3b856b4e9683e41b4e47381159.pdf
    • https://static.usrfiles.com/ugd/d01287_3f549c080cd743e6a5a95a303530c8ce.pdf
    • https://static.usrfiles.com/ugd/ea2c45_129cf9c9eaf24b28ab93d4718165ae5d.pdf
    • https://static.usrfiles.com/ugd/0c4177_227070699a5b444ba909dc401f1c79ad.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/3365514284.pdf
    • https://cdn.shopify.com/s/files/1/0433/6022/3397/files/90434761431.pdf
    • https://cdn.shopify.com/s/files/1/0435/5407/8871/files/making_love_out_of_nothing_at_all_lyrics.pdf
    • https://cdn.shopify.com/s/files/1/0434/4361/7958/files/apache_poi_excel.pdf
    • https://cdn.shopify.com/s/files/1/0434/6642/4477/files/pexusinasipigipoluzopodep.pdf
    • https://cdn.shopify.com/s/files/1/0433/4351/1706/files/wisurajowa.pdf
    • https://cdn.shopify.com/s/files/1/0430/3755/6889/files/gold_dust_conan_exiles.pdf
    • https://cdn.shopify.com/s/files/1/0438/1265/1170/files/break_from_toronto_mp3.pdf
    • https://cdn.shopify.com/s/files/1/0431/8176/8864/files/78981766858.pdf
    • https://static.usrfiles.com/ugd/529dbf_b5c04525002e464c9322a60d1db463a3.pdf
    • https://static.usrfiles.com/ugd/31593d_aa62e1486960468b9c93bc6adbaa4589.pdf
    • https://static.usrfiles.com/ugd/c81504_ba1743fac12d4f249a67622b051ed58a.pdf
    • https://static.usrfiles.com/ugd/913720_b51c81a8c2cb4804b707667d39876a4a.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010c95.bin
843785b6f6b18d44460f5cd99e92e01824c1456ee060ddcbc300befb2641a370
pdf-font-stream PDF embedded font (sfnt) at offset 0x10C95 5124 bytes
font_01_sfnt_off00011deb.bin
4438a7299221cafc2fb91882200fd497a7b9b1ff9603e5c61001294aad5f4927
pdf-font-stream PDF embedded font (sfnt) at offset 0x11DEB 9988 bytes
font_02_sfnt_off00013fd2.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0x13FD2 4324 bytes