Malicious PDF — malware analysis report

Static analysis result for SHA-256 d1ff5d8158b5e623…

MALICIOUS

PDF

43.3 KB Created: 2020-08-30 20:42:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: beffa2692e9cec329012ef08a6b464cd SHA-1: 43e1612049c1757b0fc8a5b8f6b1d6bf512d1de6 SHA-256: d1ff5d8158b5e623de30119787704ee77d4d65f8727685300c9fa6c51974d370
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a link to a malicious redirector at 'https://ttraff.cc/wix?keyword=citroen+c4+grand+picasso+haynes+manu', which is flagged as critical. The document body, though heavily obfuscated, contains text suggesting it is a 'Citroen c4 grand picasso haynes manu', indicating a lure to trick users into clicking the malicious link. The PDF also hosts a large number of external links, many pointing to Shopify domains, suggesting a link farm for SEO manipulation or to obscure the final malicious destination.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=citroen+c4+grand+picasso+haynes+manu
    • https://cdn.shopify.com/s/files/1/0436/8937/7945/files/numikifufav.pdf
    • https://cdn.shopify.com/s/files/1/0430/6596/6754/files/pifawaxaralifugidutom.pdf
    • https://cdn.shopify.com/s/files/1/0430/3667/2162/files/apc_jeans_fit_guide.pdf
    • https://cdn.shopify.com/s/files/1/0438/0947/2669/files/zifowaw.pdf
    • https://static.usrfiles.com/ugd/e5a943_01e059220d9741739aee947b4e95b136.pdf
    • https://static.usrfiles.com/ugd/299074_a3ba82c8a2b6425494cc1970304d9e29.pdf
    • https://static.usrfiles.com/ugd/79cb75_2d58fc4a76494a2498ff8fd6adba4bc1.pdf
    • https://static.usrfiles.com/ugd/314c35_714c7da364fd46a7afa1f2cf34468585.pdf
    • https://cdn.shopify.com/s/files/1/0428/8105/6935/files/xotibez.pdf
    • https://cdn.shopify.com/s/files/1/0456/8249/1551/files/adobe_maker_not_working.pdf
    • https://cdn.shopify.com/s/files/1/0431/7079/1573/files/wukamitubugo.pdf
    • https://cdn.shopify.com/s/files/1/0435/7026/6273/files/bagatowimenarojavuj.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005fb0.bin
390ce25a010331dee3f0b1d3ef8427c181fce7ff2919ceb7b515b8eec43e6131
pdf-font-stream PDF embedded font (sfnt) at offset 0x5FB0 5552 bytes
font_01_sfnt_off0000726f.bin
d1ad8b8bf91b932db150ea21050b833d616820761ac5a1d6ffe4a6997349afaf
pdf-font-stream PDF embedded font (sfnt) at offset 0x726F 14836 bytes