Malicious PDF — malware analysis report

Static analysis result for SHA-256 b6c114748def9c32…

MALICIOUS

PDF

53.7 KB Created: 2020-08-15 06:01:19 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c1f2291673ce5556787cb0cb87eb6212 SHA-1: dc4ce79fced9ef9f37b2201e0b6ed2a7bdb891c8 SHA-256: b6c114748def9c3281410e1d484b7ca745216aec4a4a0f2a363f538e6cf18541
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, many of which point to Shopify domains hosting other PDFs, but one critical link directs to 'ttraff.ru', a known malicious redirector. The document body, though heavily obfuscated, contains the same lure text and the malicious URL, indicating an attempt to trick users into visiting the redirector for potentially harmful content. No scripts were extracted, but the PDF structure itself is used for the malicious redirection.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=chokher+bali+full+movie++kickass
    • http://files.apparelcolorwork.com/uploads/1/3/1/6/131606854/4683207.pdf
    • http://files.judydunaway.com/uploads/1/3/0/8/130874120/ec12cf760b.pdf
    • http://vedipu.scrapbookcreationsny.com/uploads/1/3/0/7/130775318/9a6a390433f.pdf
    • http://files.inyfilmfest.com/uploads/1/3/1/4/131453605/91b5a6ccfa31.pdf
    • http://files.pleasantlivingmagazine.com/uploads/1/3/0/7/130774990/8eb868aca3b8.pdf
    • https://cdn.shopify.com/s/files/1/0431/8684/7905/files/41686357682.pdf
    • https://cdn.shopify.com/s/files/1/0431/8534/0580/files/36338396664.pdf
    • https://cdn.shopify.com/s/files/1/0438/2598/7734/files/project_plan_template_google_sheets.pdf
    • https://cdn.shopify.com/s/files/1/0437/5491/3950/files/battle_born_deluxe_edition.pdf
    • https://cdn.shopify.com/s/files/1/0437/2067/1400/files/ielts_reading_practice_test_2020_with_answers.pdf
    • https://cdn.shopify.com/s/files/1/0438/8998/3640/files/19867907996.pdf
    • https://cdn.shopify.com/s/files/1/0434/0780/2518/files/86664546761.pdf
    • https://cdn.shopify.com/s/files/1/0451/2504/2329/files/employee_benefits_guide_examples.pdf
    • https://cdn.shopify.com/s/files/1/0430/6511/4775/files/nugelike.pdf
    • https://cdn.shopify.com/s/files/1/0430/4519/1841/files/certificat_de_cession_voiture.pdf
    • https://cdn.shopify.com/s/files/1/0440/8786/9592/files/72307339095.pdf
    • https://cdn.shopify.com/s/files/1/0436/1430/6466/files/the_f_formula_marni.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006c78.bin
0593d514a312197e9079291ed11d0593ad062e239563188786f49ae6a3505548
pdf-font-stream PDF embedded font (sfnt) at offset 0x6C78 5292 bytes
font_01_sfnt_off00007e53.bin
cf2b3807f2e8a90711b871d2219bc9dd78390bf679e090af1fcdabdb1a7d8fd0
pdf-font-stream PDF embedded font (sfnt) at offset 0x7E53 4764 bytes
font_02_sfnt_off00008d4f.bin
27140b2eea6855e5d1b8cdfa133ff32d43e944d8839d564c6aa6560109fc2b29
pdf-font-stream PDF embedded font (sfnt) at offset 0x8D4F 10572 bytes
font_03_sfnt_off0000b1c7.bin
e296a61d2d303e35be9e1a35631556663d2780498efa7e8f3867bf557f172fe6
pdf-font-stream PDF embedded font (sfnt) at offset 0xB1C7 16164 bytes