Malicious PDF — malware analysis report

Static analysis result for SHA-256 8d7e6d2d922fc615…

MALICIOUS

PDF

39.7 KB Created: 2020-08-14 23:24:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b53746913df6b7313525cfab936563d8 SHA-1: 1b007ca2074f696cb9f679bdcbb336dd19b6c003 SHA-256: 8d7e6d2d922fc6150598a365d78b973e0a899f45660ee2164c1e05275a3ecb7c
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a heuristic firing for a malicious redirector link pointing to 'ttraff.ru', which is associated with a link farm. The document body, though heavily obfuscated, contains the same URL. The PDF also contains numerous embedded links, many hosted on Shopify, but the primary malicious indicator is the ttraff.ru redirector. The presence of multiple embedded links and the redirector suggests a phishing or scam attempt to lead the user to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wb?keyword=connectives%20worksheets%20year%202
    • http://vuwokori.holapetinn.com/uploads/1/3/0/7/130776406/xedaxemisi.pdf
    • http://files.communityactionboonewinn.org/uploads/1/3/2/6/132681293/78b0fb1ed6.pdf
    • https://cdn.shopify.com/s/files/1/0440/5228/3542/files/lovonaxoxekanifomaxoni.pdf
    • https://cdn.shopify.com/s/files/1/0438/0616/3104/files/youtube_embed_autoplay.pdf
    • https://cdn.shopify.com/s/files/1/0432/3488/5796/files/gijofararodivirelimelifu.pdf
    • https://cdn.shopify.com/s/files/1/0434/8251/3561/files/nanemuvadiviresu.pdf
    • https://cdn.shopify.com/s/files/1/0430/6275/5490/files/totogenobuvixobisa.pdf
    • https://cdn.shopify.com/s/files/1/0428/3957/2643/files/mopuviraletozatilif.pdf
    • https://cdn.shopify.com/s/files/1/0435/0813/8150/files/43891858290.pdf
    • https://cdn.shopify.com/s/files/1/0430/5548/0981/files/management_representation_letter.pdf
    • https://cdn.shopify.com/s/files/1/0437/7437/8142/files/4_team_round_robin.pdf
    • https://cdn.shopify.com/s/files/1/0431/9277/8901/files/zeparorogirazosikoxilu.pdf
    • https://cdn.shopify.com/s/files/1/0431/8615/9767/files/narepigukejiwodajuliwel.pdf
    • https://cdn.shopify.com/s/files/1/0431/3019/2039/files/nubadepuzoluwob.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005dad.bin
39de079ed7bf162cbedd01823f5dea52bc854e27d3adfa5d74aa0a1db2ea5647
pdf-font-stream PDF embedded font (sfnt) at offset 0x5DAD 5208 bytes
font_01_sfnt_off00006f73.bin
8e5bf9e45b3bebffd5cf9b0b920a842eaea6fb3fe6c26596a639e3f3326f28a2
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F73 10228 bytes