Malicious PDF — malware analysis report

Static analysis result for SHA-256 d4d012b66a4e56f0…

MALICIOUS

PDF

52.9 KB Created: 2020-09-01 06:00:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 075ef5049710e4dbf1bb84712f42ec4c SHA-1: b7f891a06dcab053ab5fd0027c01d3433bf9ced9 SHA-256: d4d012b66a4e56f0e22446ae7ecda4b1214d21e606deb2c9c49342fbe04b7e01
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a mass external link farm, with a primary malicious redirector link pointing to 'https://ttraff.cc/wix?keyword=marketing+information+system+meaning'. This indicates a social engineering attempt to direct users to malicious infrastructure. The document body, though heavily obfuscated, contains the same keyword, reinforcing the lure. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=marketing+information+system+meaning
    • https://cdn.shopify.com/s/files/1/0434/4774/6721/files/networking_class_a_b_c.pdf
    • https://cdn.shopify.com/s/files/1/0430/6193/6285/files/9609327678.pdf
    • https://cdn.shopify.com/s/files/1/0432/9593/2574/files/75187113637.pdf
    • https://cdn.shopify.com/s/files/1/0434/8814/9654/files/87641629469.pdf
    • https://static.usrfiles.com/ugd/defdb4_5e9260b6240f4476b11595577461afcc.pdf
    • https://cdn.shopify.com/s/files/1/0431/3802/3581/files/finder_forcibly_guided_contacts.pdf
    • https://cdn.shopify.com/s/files/1/0435/4464/1695/files/exception_in_thread_main_java._lang._numberformatexception.pdf
    • https://cdn.shopify.com/s/files/1/0440/4156/8421/files/33566532075.pdf
    • https://cdn.shopify.com/s/files/1/0435/0525/4566/files/cristianismo_puro_e_simples_download_gratis.pdf
    • https://cdn.shopify.com/s/files/1/0445/3901/9428/files/81257532173.pdf
    • https://cdn.shopify.com/s/files/1/0431/1603/6257/files/riragiwebek.pdf
    • https://cdn.shopify.com/s/files/1/0433/6756/3418/files/56221577372.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000091f2.bin
0140cd6c47f8e57c1d2e71fb0749c7d3df152958eac181979d2f2ef96ede6249
pdf-font-stream PDF embedded font (sfnt) at offset 0x91F2 5228 bytes
font_01_sfnt_off0000a3c5.bin
86867126406bb0791c1501a1950295566757b38886e6b7a2a9072d26c93eb4b3
pdf-font-stream PDF embedded font (sfnt) at offset 0xA3C5 10332 bytes