Malicious PDF — malware analysis report

Static analysis result for SHA-256 86d2b1cbdd05f2a1…

MALICIOUS

PDF

45.9 KB Created: 2020-09-02 15:06:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 01eb3c8d7741b61b909d6e4ef3ff4542 SHA-1: 0819fd9bb5a026ea2847287e298e6db473cf913c SHA-256: 86d2b1cbdd05f2a150aa82c4d7dda1c6858f37243a90566a1291aa9682dae6d6
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.club/wix?keyword=factor+polynomials+worksheet+pdf'. This URL is presented within the document body, disguised as a worksheet title. The PDF also exhibits characteristics of a link farm, with numerous embedded URLs, many pointing to 'static.usrfiles.com'. The ML classifier strongly flagged this PDF as malicious. The primary attack vector appears to be social engineering, luring the user to a malicious site under the guise of educational content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=factor+polynomials+worksheet+pdf
    • https://static.usrfiles.com/ugd/b8c837_41b445d729604eb491da607c374981f2.pdf
    • https://static.usrfiles.com/ugd/89602e_4437ecf38cb4486aa344ab5c7c8167e0.pdf
    • https://static.usrfiles.com/ugd/6290de_b674d72a9c844072a9d9de271c79ccc6.pdf
    • https://static.usrfiles.com/ugd/94e5ef_96fc398ca52249bcbd9719ecb307a68a.pdf
    • https://static.usrfiles.com/ugd/865d50_429e5413f94f4f248adf508112f0fa3a.pdf
    • https://cdn.shopify.com/s/files/1/0435/3890/7288/files/xisos.pdf
    • https://cdn.shopify.com/s/files/1/0440/9052/3813/files/wedes.pdf
    • https://cdn.shopify.com/s/files/1/0430/6806/3895/files/60587009843.pdf
    • https://cdn.shopify.com/s/files/1/0431/7147/9713/files/adobe_camera_raw_converter.pdf
    • https://cdn.shopify.com/s/files/1/0435/3431/9776/files/watazepaza.pdf
    • https://cdn.shopify.com/s/files/1/0428/1883/0503/files/tikez.pdf
    • https://cdn.shopify.com/s/files/1/0431/2340/9057/files/78407519377.pdf
    • https://static.usrfiles.com/ugd/4c3ae3_28de737cd2fa4f169c69349dec3c1a72.pdf
    • https://static.usrfiles.com/ugd/3b0c81_e5f1b6614c9a4269bb009679f8e159da.pdf
    • https://static.usrfiles.com/ugd/30e015_f3525cf9a0a84772becacc6a342d57e5.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000671d.bin
6fa631a57dc457c78475bacb9ef2ea412f73984ef318da8fb014a53d7a4dfa2a
pdf-font-stream PDF embedded font (sfnt) at offset 0x671D 5396 bytes
font_01_sfnt_off0000795e.bin
fba38de618ca1a9f8c300a55916216bef6ab536bf76c13414128806f8cc65b6f
pdf-font-stream PDF embedded font (sfnt) at offset 0x795E 10428 bytes
font_02_sfnt_off00009cd3.bin
ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3
pdf-font-stream PDF embedded font (sfnt) at offset 0x9CD3 4324 bytes