Malicious PDF — malware analysis report

Static analysis result for SHA-256 b43b8632ee92fa48…

MALICIOUS

PDF

34.0 KB Created: 2020-09-18 04:39:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b42634ca6fd130d6f0c392b3801800b1 SHA-1: 9443e18ee97dbb6027005b113e47217a485dc8bf SHA-256: b43b8632ee92fa4848f93808e1ad94d4fe6406a7e2c7a88e0a8557b27c2e4312
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a mass external link farm, with many links pointing to Shopify-hosted PDFs, likely as a SEO-based lure. One critical heuristic identified a link to a known malicious redirector, https://ttraff.link/wix?keyword=acma+study+guide+login, which is the primary IOC. The document body, though heavily obfuscated, contains this URL and references 'acma study guide login', suggesting a phishing or credential harvesting pretext. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=acma+study+guide+login
    • http://jawaromus.forthillgospelhall.com/uploads/1/3/1/3/131380969/4865376.pdf
    • http://files.langsidebedandbreakfast.com/uploads/1/3/1/3/131398322/lelovizosujo_sunijefavu_mikaxeno_gekamuvazotiz.pdf
    • http://files.tonyandersen.com/uploads/1/3/0/9/130969714/b69df731aad.pdf
    • https://cdn.shopify.com/s/files/1/0431/7623/1072/files/wabixem.pdf
    • https://cdn.shopify.com/s/files/1/0486/9501/7622/files/71413002696.pdf
    • https://cdn.shopify.com/s/files/1/0428/6719/6063/files/farid_al-_din_attar.pdf
    • https://cdn.shopify.com/s/files/1/0430/5921/6537/files/ff14_gunbreaker_guide_deutsch.pdf
    • https://bf2ab296-aa44-4fd7-9f11-0a42c128103e.filesusr.com/ugd/b0c717_2c05035e68e54241b99a714a590784ee.pdf?index=true
    • https://b126585b-16d9-4727-8609-b53f1643eae3.filesusr.com/ugd/8d46c2_c894e5001cb44bd1a18309051ca0b266.pdf?index=true
    • https://d0984175-268b-49d5-b375-0557a89b330f.filesusr.com/ugd/a6e5e9_945dcc2326fe4466b2a01f6e02cc6ebf.pdf?index=true
    • https://5bb75274-7356-427f-a809-48bbedc96d8f.filesusr.com/ugd/ae15ca_de8a8b11a6e8476ea99dd17df696bffc.pdf?index=true
    • https://c27d1cff-c58f-439a-9601-62f224232392.filesusr.com/ugd/a51aec_cc1251f6970245aea9cb895edd307842.pdf?index=true
    • https://d442b3dc-affc-4c77-9ee9-e1428107f38c.filesusr.com/ugd/d902bb_14c58368e02445d5ab64da93c1bcc45c.pdf?index=true
    • https://c9ad8b62-bd55-4890-bbf5-a61b38df5671.filesusr.com/ugd/3bcfef_3b8e78cc772e4df893e29f895da4fb17.pdf?index=true
    • https://1ac2d501-7579-4cdc-b730-7e474f60ad9a.filesusr.com/ugd/60e703_7d6c6fbae44a43a3814916397246c65d.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000047da.bin
53ab4ee3278276d8b5d1b91fc0bd3b05c5c290f8d4d685a417dc49d80b172981
pdf-font-stream PDF embedded font (sfnt) at offset 0x47DA 5256 bytes
font_01_sfnt_off000059b2.bin
fb1b657fa2d414bf3b790711ef5275eb861cf8c761503951c864a7ab36e7f342
pdf-font-stream PDF embedded font (sfnt) at offset 0x59B2 9932 bytes