Malicious PDF — malware analysis report

Static analysis result for SHA-256 bbd75fb8f46be205…

MALICIOUS

PDF

33.7 KB Created: 2020-08-12 16:04:43 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e455646179289a50d52feb7caddda34d SHA-1: 72a74a60822dd506717322011f4f68379b0d9041 SHA-256: bbd75fb8f46be2057b7c7a88abe158a49ab8ccc75d099591e9079a6a0c32d425
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a machine learning classifier and heuristics indicate it contains a malicious redirector link and a large number of external PDF links, suggesting an SEO farm or redirection attack. The primary malicious URL identified is ttraff.ru, which is used in conjunction with a keyword related to Canadian maps. The document body contains garbled text but also includes the malicious URL and several Shopify URLs, some of which are benign and others are unknown.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=canada+bc+map+pdf
    • http://files.z-emotion.com/uploads/1/3/1/8/131856877/7979812.pdf
    • http://kuzilot.highdene.com/uploads/1/3/1/6/131606289/xegide.pdf
    • http://nuzami.sophiehacker.com/uploads/1/3/0/7/130776485/noxezimobifu_siwon.pdf
    • https://cdn.shopify.com/s/files/1/0431/0204/4316/files/xizutetitomoviginuke.pdf
    • https://cdn.shopify.com/s/files/1/0430/2936/4885/files/60342382343.pdf
    • https://cdn.shopify.com/s/files/1/0433/3587/6776/files/60577550643.pdf
    • https://cdn.shopify.com/s/files/1/0427/7898/4614/files/35299288772.pdf
    • https://cdn.shopify.com/s/files/1/0433/2204/8667/files/agreement_on_the_application_of_sanitary_and_phytosanitary_measures.pdf
    • https://cdn.shopify.com/s/files/1/0433/4046/4281/files/actron_cp9125_codes.pdf
    • https://cdn.shopify.com/s/files/1/0434/5180/9957/files/lexekapopibebikos.pdf
    • https://cdn.shopify.com/s/files/1/0437/6641/5514/files/55365121862.pdf
    • https://cdn.shopify.com/s/files/1/0435/9120/5021/files/73134782566.pdf
    • https://cdn.shopify.com/s/files/1/0437/3823/5031/files/zaxifuso.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004681.bin
3d68550050b52e7a3476679f4d298250190c3ee82168be2a04a2f03f27ea5b2f
pdf-font-stream PDF embedded font (sfnt) at offset 0x4681 5040 bytes
font_01_sfnt_off00005793.bin
ace1a30a5b2318ff422aadcb8d51668210d9dbdb3e9afa29a8c9615c90880752
pdf-font-stream PDF embedded font (sfnt) at offset 0x5793 10192 bytes