Malicious PDF — malware analysis report

Static analysis result for SHA-256 c868df60aee6a72f…

MALICIOUS

PDF

120.0 KB Created: 2020-08-31 03:47:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b68d795c60ca7913cd44a45921081964 SHA-1: 70f7a5603b63de774a4eab25ba9a759ae145b62e SHA-256: c868df60aee6a72fdee70ff3a5488d4bc9fa5119d8373cf338dcb931ee5d05fe
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF was flagged as malicious due to a critical heuristic firing for a redirector link pointing to `https://ttraff.ru/wix?keyword=le+feu+est+allum%25C3%25A9+aujourd%2527hui+partit`. This URL is likely part of a phishing or malware distribution chain. The document body, though heavily obfuscated, contains this same URL, reinforcing its malicious intent. The presence of numerous other links, while many are benign, suggests a link farm or SEO poisoning tactic to obscure the malicious destination.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=le+feu+est+allum%25C3%25A9+aujourd%2527hui+partit
    • https://static.usrfiles.com/ugd/cafc24_9c1c2631fe104cf48842fa611f896fbc.pdf
    • https://static.usrfiles.com/ugd/b8c837_2f68eb444f0f46489efea14ce3ee0019.pdf
    • https://static.usrfiles.com/ugd/b444d4_2dc9a0f1e452443598191be20ea63528.pdf
    • https://static.usrfiles.com/ugd/ca300b_0b9fdd1f02fc4822ba5245dae96da776.pdf
    • https://static.usrfiles.com/ugd/b8c837_7164653375814b81ac3ed7067aff12c3.pdf
    • https://static.usrfiles.com/ugd/07625c_0902f4d2509d4c399a6d8862ffe48aef.pdf
    • https://cdn.shopify.com/s/files/1/0435/9349/8787/files/android_aapt2_process_unexpectedly_exit.pdf
    • https://cdn.shopify.com/s/files/1/0432/4642/0132/files/74828868014.pdf
    • https://cdn.shopify.com/s/files/1/0436/1689/5133/files/bangla_natok_2019_video.pdf
    • https://cdn.shopify.com/s/files/1/0428/0736/1703/files/numovixinifevalobarufaf.pdf
    • https://cdn.shopify.com/s/files/1/0433/1179/2286/files/99293819820.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/febipak.pdf
    • https://cdn.shopify.com/s/files/1/0430/6301/7629/files/totemazabusalosifun.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000170a1.bin
151309a0de9b19968530f65d7f8fa7aeb9c59a9ea07a8a8eb97d0ae7acdab78e
pdf-font-stream PDF embedded font (sfnt) at offset 0x170A1 5476 bytes
font_01_sfnt_off000182e4.bin
4b735bb9475c548f07ede30dc80c96d6540fc4e2d865d727d0227e8908204fdc
pdf-font-stream PDF embedded font (sfnt) at offset 0x182E4 19500 bytes
font_02_sfnt_off0001bb60.bin
99ddc6f5858eb134f8024171ebe717cbd02485c31471b921a5021903b5272953
pdf-font-stream PDF embedded font (sfnt) at offset 0x1BB60 16060 bytes