Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b2bae8110190e20…

MALICIOUS

PDF

51.5 KB Created: 2020-08-31 19:12:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a657c10515e366f63e4bde8d3a06a023 SHA-1: cd1d0a11f8aa6b98b5c47f0a609fd043a7ade35c SHA-256: 8b2bae8110190e20538aa7985876389987c58d303369a8ef70b8148ec37e9842
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a significant number of embedded links, identified as a link farm. One of these links, 'https://ttraff.com/wix?keyword=avramis+river+indicator', points to known malicious redirector infrastructure. The document body itself is heavily obfuscated and contains this same URL, suggesting it is the primary lure. The presence of numerous other links, many pointing to Shopify domains, indicates a strategy to obscure the malicious destination and potentially leverage seemingly benign hosting for distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=avramis+river+indicator
    • https://static.usrfiles.com/ugd/9c0842_46c55af44b81426fbb9dfdc87c638e4a.pdf
    • https://static.usrfiles.com/ugd/c1de29_745a761babb14d51b53726b35b9940e3.pdf
    • https://static.usrfiles.com/ugd/4dd980_7af225c40b61411ca08f26dea4ddee79.pdf
    • https://static.usrfiles.com/ugd/98857b_37cd5154bde943ddbc45b6cda3acf780.pdf
    • https://static.usrfiles.com/ugd/b8c837_6b6d999c51a34c7996ee9ac66540983d.pdf
    • https://cdn.shopify.com/s/files/1/0437/9112/2584/files/getedazigevipokorakorof.pdf
    • https://cdn.shopify.com/s/files/1/0429/4436/4710/files/99512380757.pdf
    • https://cdn.shopify.com/s/files/1/0431/5503/0170/files/associated_spring_catalog.pdf
    • https://cdn.shopify.com/s/files/1/0431/2779/9969/files/kefijelumipelemuv.pdf
    • https://cdn.shopify.com/s/files/1/0431/1020/3556/files/rulers_of_evil_review.pdf
    • https://cdn.shopify.com/s/files/1/0433/1572/4456/files/55322536588.pdf
    • https://cdn.shopify.com/s/files/1/0433/4914/7816/files/41476878069.pdf
    • https://cdn.shopify.com/s/files/1/0434/2258/0886/files/what_is_baseline_survey_report.pdf
    • https://cdn.shopify.com/s/files/1/0433/1667/4713/files/napopezofawa.pdf
    • https://static.usrfiles.com/ugd/9219f8_6db19bc9c9bc4d7ca1ee63e7a5f3c075.pdf
    • https://static.usrfiles.com/ugd/ce14f3_5bc6e75edd3a477990333654be5203e1.pdf
    • https://static.usrfiles.com/ugd/b8c837_4adedca71c6249a7bcc29ecf813a5d93.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000053e3.bin
bff169657fc63e9cae268a1f25205ba16e4ea6ce578ce0133a273f0c3b729c06
pdf-font-stream PDF embedded font (sfnt) at offset 0x53E3 12140 bytes
font_01_sfnt_off00007bb4.bin
f34290b2d43dc50573cf3c230b60d7ed5a68cf95d203f30c50a79b893082c4b0
pdf-font-stream PDF embedded font (sfnt) at offset 0x7BB4 5100 bytes
font_02_sfnt_off00008ced.bin
b455134215c1f127543c9e9325f175308c359cbf98b278a12a4b01fea3a88c9a
pdf-font-stream PDF embedded font (sfnt) at offset 0x8CED 6092 bytes
font_03_sfnt_off00009cc0.bin
c647bc2e3ce7397c73df13f3e9b3d583aeb655586f1d2f91b68b2baa8e8b906d
pdf-font-stream PDF embedded font (sfnt) at offset 0x9CC0 10492 bytes