Malicious PDF — malware analysis report

Static analysis result for SHA-256 c1d7afe53f95cba8…

MALICIOUS

PDF

43.8 KB Created: 2020-09-02 22:34:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 02e9360f98f4c5b150e10f357522bf4c SHA-1: 91cc8853c517dce8ae10683b66b59ea48e14a7c0 SHA-256: c1d7afe53f95cba83027b6313c994a54552cca9e70d09c03a7a354d5d2744a71
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, a technique often used in SEO link farms to manipulate search engine rankings or distribute malicious content. One of the primary links, 'https://ttraff.link/pify?keyword=sound+of+silence+disturbed+tab+pdf', is flagged as a known malicious redirector. The ML classifier also strongly indicated maliciousness. The document body appears to be obfuscated or corrupted, but the presence of the malicious redirector URL is the primary indicator of compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/pify?keyword=sound+of+silence+disturbed+tab+pdf
    • https://static.usrfiles.com/ugd/97368a_9b22fc9916f243e79fee4e5ed2ca8ba2.pdf
    • https://static.usrfiles.com/ugd/cc3ca9_9201ffd2a0184ceea06d812353c7e42e.pdf
    • https://static.usrfiles.com/ugd/0d002d_796bd5fc7ac84c75832727af0a86f360.pdf
    • https://static.usrfiles.com/ugd/a86d68_5f6c797265b341f181d7ae176acafaa9.pdf
    • https://static.usrfiles.com/ugd/229b11_576e5505104a4b32ad9cadc1a69b469e.pdf
    • https://static.usrfiles.com/ugd/9219f8_75061474eea9489684d5a71fefba52fc.pdf
    • https://static.usrfiles.com/ugd/0c268c_418d38a5cd98469ba308ed5188d505a8.pdf
    • https://static.usrfiles.com/ugd/07e02c_6bd4236edeca4ba2a7fc9efa9e8a0192.pdf
    • https://cdn.shopify.com/s/files/1/0440/4979/3174/files/copleston_history_of_philosophy_complete_set.pdf
    • https://cdn.shopify.com/s/files/1/0440/2947/7014/files/30048374977.pdf
    • https://cdn.shopify.com/s/files/1/0459/9473/7821/files/kufubelosebakebufalegagog.pdf
    • https://static.usrfiles.com/ugd/2f3ac6_b7df54273cbb465180b14b7f7f2cdd35.pdf
    • https://static.usrfiles.com/ugd/865d50_6c6227bc60e44094bb4c7e492dbf2d5e.pdf
    • https://static.usrfiles.com/ugd/b8c837_846b09febf96493084f20af08920a2be.pdf
    • https://static.usrfiles.com/ugd/b8c837_8d8d8e51abbd4a3788e7fde0195f5ae2.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004c14.bin
6fb653fe9fa59dcbc36092c088def4cd671aa6803126f0f433e68341e124ad7c
pdf-font-stream PDF embedded font (sfnt) at offset 0x4C14 5392 bytes
font_01_sfnt_off00005e6c.bin
4139811c2cdc1471419420b69a19d9e1c25f3c1ef26ee381d9b88caf0694b2e7
pdf-font-stream PDF embedded font (sfnt) at offset 0x5E6C 8108 bytes
font_02_sfnt_off000074e3.bin
8ca51c0b79eecde5e3a327a23fb8b9520ea0f97c6f52eb3eb4dd59708cd8a214
pdf-font-stream PDF embedded font (sfnt) at offset 0x74E3 13496 bytes