Malicious PDF — malware analysis report

Static analysis result for SHA-256 b5e518ab6eadf62e…

MALICIOUS

PDF

53.2 KB Created: 2020-08-11 02:47:46 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 98ec819158a9847349dda31d221ed143 SHA-1: 55ad8b7d2bb3ef0ad7af66a6e492877b72be057a SHA-256: b5e518ab6eadf62e2f8003106d316fc954edaaed73bcea7a51efd8f3fbba7f96
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, many of which point to Shopify domains, but one critical link redirects to a known malicious domain, ttraff.ru. This domain is used as a redirector, likely to obscure the final malicious destination. The document body, though heavily obfuscated, contains the same malicious URL, suggesting it's the primary lure. The presence of numerous PDF links, many generated with numeric or book slugs, indicates a link farm SEO tactic to improve search engine visibility for the malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=hepatic+abscess+guidelines+management+pdf+2020
    • http://woveti.mysanelife.com/uploads/1/3/1/4/131407995/bedagajufebufir_vawirofikip_xipudigemun_setojeb.pdf
    • http://files.lagrangebennac.com/uploads/1/3/1/4/131407164/ad9f1bd5.pdf
    • http://files.thecornersheffield.com/uploads/1/3/0/7/130740323/1932062.pdf
    • http://files.micim.com/uploads/1/3/1/6/131636764/mafirerizofuzebuwa.pdf
    • https://cdn.shopify.com/s/files/1/0438/0049/4237/files/maxesevidilopiziraxezif.pdf
    • https://cdn.shopify.com/s/files/1/0428/1712/6567/files/12311678683.pdf
    • https://cdn.shopify.com/s/files/1/0445/6343/1588/files/cg_police_sub_inspector_syllabus.pdf
    • https://cdn.shopify.com/s/files/1/0433/1778/8830/files/10943443373.pdf
    • https://cdn.shopify.com/s/files/1/0429/2332/7644/files/destiny_2_fireteam_leader.pdf
    • https://cdn.shopify.com/s/files/1/0430/5354/7677/files/an_introduction_to_statistical_learning_with_applications_in_python.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/gerakofidasetivivirodipel.pdf
    • https://cdn.shopify.com/s/files/1/0433/3050/2806/files/anyone_anything_someone_something_exercises.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/7997453156.pdf
    • https://cdn.shopify.com/s/files/1/0432/5317/0334/files/82429159461.pdf
    • https://cdn.shopify.com/s/files/1/0430/7599/3764/files/diviresigugajukixesa.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009011.bin
fa53853f96ef7a496892356349289f8c4c7841a475fa8694ee48ebe15c5c2328
pdf-font-stream PDF embedded font (sfnt) at offset 0x9011 5756 bytes
font_01_sfnt_off0000a38c.bin
0ce9a41c9e3643c8f4e21c1ae1853920e82bcb8ceb4638af41ed49d51b9dd468
pdf-font-stream PDF embedded font (sfnt) at offset 0xA38C 10580 bytes