Malicious PDF — malware analysis report

Static analysis result for SHA-256 c359ba11a4632b81…

MALICIOUS

PDF

63.0 KB Created: 2020-08-29 15:12:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a76ef61dda4656fb339581a238e8a105 SHA-1: 1a1450ee2da655159734154db27b41aec689b858 SHA-256: c359ba11a4632b81b85f11022acd2e64dbd2fb2687393ea3b6912a7be41acd37
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.ru/wix?keyword=apostila+anglo+3+ano+ensino+fundamental+pdf'. Additionally, another critical heuristic indicates a PDF link farm, suggesting an attempt to distribute malicious content. The ML classifier also strongly flagged this PDF as malicious. The document body, though partially corrupted, contains the same malicious URL, reinforcing the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=apostila+anglo+3+ano+ensino+fundamental+pdf
    • https://cdn.shopify.com/s/files/1/0433/1310/2998/files/51744859142.pdf
    • https://cdn.shopify.com/s/files/1/0435/3094/4671/files/r_kelly_birthday_song_free_mp3_download.pdf
    • https://cdn.shopify.com/s/files/1/0435/2878/1973/files/gimitiwenenimutetiveluluf.pdf
    • https://cdn.shopify.com/s/files/1/0431/4680/5404/files/66880433411.pdf
    • https://static.usrfiles.com/ugd/b8c837_bec8841ca7bc4414be601f9d0ff2c196.pdf
    • https://static.usrfiles.com/ugd/b8c837_a3bb013c06c34e6aa3ca6e2b8b29ce4d.pdf
    • https://static.usrfiles.com/ugd/b8c837_aed81ba7b08a47d29e8023889db43d12.pdf
    • https://static.usrfiles.com/ugd/b8c837_672df19a5cb5463dae8a535bd7d428c0.pdf
    • https://static.usrfiles.com/ugd/b8c837_209cea2bae7245a0a6236b62b357853e.pdf
    • https://cdn.shopify.com/s/files/1/0462/4377/4618/files/reliance_annual_report_2018-_19.pdf
    • https://cdn.shopify.com/s/files/1/0431/1767/4656/files/biography_of_abraham_lincoln_in_english.pdf
    • https://cdn.shopify.com/s/files/1/0439/5125/9803/files/google_doc_template_meeting_minutes.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008259.bin
b29f9350a720d2da9dc50567d08c4a82684db1fcb28a47e3a5788345b392d808
pdf-font-stream PDF embedded font (sfnt) at offset 0x8259 6744 bytes
font_01_sfnt_off0000933e.bin
b13cd5dbab07ef9f3b84f7cc66f8c66f081774e2df3d947931d6fd5358bcf7f8
pdf-font-stream PDF embedded font (sfnt) at offset 0x933E 5300 bytes
font_02_sfnt_off0000a527.bin
ad8b0158a98297d06690cffa6db8a69147138be217e88ce33b582c31304d2232
pdf-font-stream PDF embedded font (sfnt) at offset 0xA527 1680 bytes
font_03_sfnt_off0000ad76.bin
59adb3cc787da4f8f4be85e50d6b3cb343cd22767ba1d813168453303842f919
pdf-font-stream PDF embedded font (sfnt) at offset 0xAD76 17184 bytes
font_04_sfnt_off0000e051.bin
1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361
pdf-font-stream PDF embedded font (sfnt) at offset 0xE051 4324 bytes