Malicious PDF — malware analysis report

Static analysis result for SHA-256 bd0e957a1b5f5730…

MALICIOUS

PDF

57.5 KB Created: 2020-08-08 18:55:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bcee30f264f635d9165cc4f1713d32ea SHA-1: 8c60a4685cc944dd29aa86b7c8471548ffa857ac SHA-256: bd0e957a1b5f5730b508f63cc2aadd1c9b5f14bbf9659569aff6ce587e605596
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a significant number of embedded links, with a critical heuristic firing for a PDF link farm. One of these links, https://ttraff.ru/pify?keyword=defenseless+hearts+meagan+brandy+pdf, is identified as a known malicious redirector. The document body is heavily obfuscated and contains junk data, but the presence of the malicious redirector URL and the link farm structure strongly suggest an attempt to lure users to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=defenseless+hearts+meagan+brandy+pdf
    • http://files.veinclinicmb.com/uploads/1/3/0/8/130874317/ripajevofuw.pdf
    • http://xaxiwata.emeraldowlproductions.com/uploads/1/3/0/8/130813834/861a0e30d5.pdf
    • http://files.lawncarenewburgh.com/uploads/1/3/2/6/132682230/2997825.pdf
    • https://cdn.shopify.com/s/files/1/0428/7607/6188/files/pavumawasebemi.pdf
    • https://cdn.shopify.com/s/files/1/0431/2511/2993/files/99212265260.pdf
    • https://cdn.shopify.com/s/files/1/0428/2348/3548/files/95826039164.pdf
    • https://cdn.shopify.com/s/files/1/0429/2454/0071/files/37861460640.pdf
    • https://cdn.shopify.com/s/files/1/0432/0778/6651/files/2893048308.pdf
    • https://cdn.shopify.com/s/files/1/0427/8091/7926/files/10963564664.pdf
    • https://cdn.shopify.com/s/files/1/0434/2287/5797/files/talerofu.pdf
    • https://cdn.shopify.com/s/files/1/0429/5353/9747/files/foneretifebugufina.pdf
    • https://cdn.shopify.com/s/files/1/0436/0306/7044/files/87717839713.pdf
    • https://cdn.shopify.com/s/files/1/0434/3414/7989/files/vanemobukedupidofal.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000629f.bin
3d4760ca295192c89086870ebbac49c5a5945404ea6ab57fca452cf2db5f569a
pdf-font-stream PDF embedded font (sfnt) at offset 0x629F 6440 bytes
font_01_sfnt_off00007293.bin
034c6b7753d1ec13425ea56b1e602b1799b2cfe47d212c70cce6f989223558c5
pdf-font-stream PDF embedded font (sfnt) at offset 0x7293 5696 bytes
font_02_sfnt_off000085ca.bin
41ba78ef9fb4a5adcbf3ba654ecb65fc3e6a321a4a819e01271ead3c1544e838
pdf-font-stream PDF embedded font (sfnt) at offset 0x85CA 8360 bytes
font_03_sfnt_off00009cec.bin
bd758343f27254ba1fd65fe7cf0b1c4416a7929be706dccf6e88f1261eb23ea0
pdf-font-stream PDF embedded font (sfnt) at offset 0x9CEC 10388 bytes
font_04_sfnt_off0000c0a4.bin
41d5861addad471ea3b788cd2d5c2a981fdc395474b1185ea51f0a019783c40e
pdf-font-stream PDF embedded font (sfnt) at offset 0xC0A4 16884 bytes