Malicious PDF — malware analysis report

Static analysis result for SHA-256 d8113c7b27b0561f…

MALICIOUS

PDF

48.0 KB Created: 2020-08-22 11:17:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 06f6b2011e821b46d09a15c55514bb1f SHA-1: a3303d2b455138d629041d5fff8acc466d902f2f SHA-256: d8113c7b27b0561f8071ee87440ce163442bd8a2bc974dcfd07381c841bc5bc0
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a critical heuristic for containing a malicious redirector link to 'ttraff.ru'. Additionally, it exhibits characteristics of a PDF link farm, embedding numerous external links, many pointing to Shopify-hosted PDFs. The ML classifier also strongly indicated maliciousness. The primary attack pattern involves luring the user through these links, with the 'ttraff.ru' URL being the most suspicious, likely leading to a phishing or malware distribution site.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=it+wasn%2527+t+me+song
    • http://kukanuv.mrg-skyline.com/uploads/1/3/1/4/131454029/4740310.pdf
    • https://cdn.shopify.com/s/files/1/0429/7365/9292/files/adecco_thailand_salary_guide.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/9646434013.pdf
    • https://cdn.shopify.com/s/files/1/0433/2371/9845/files/37049064078.pdf
    • https://cdn.shopify.com/s/files/1/0461/7564/9946/files/fezemokuwumawa.pdf
    • https://cdn.shopify.com/s/files/1/0432/8954/2809/files/biblia_con_libros_apocrifos.pdf
    • https://cdn.shopify.com/s/files/1/0429/9931/6639/files/dasafuterijafivujeveduzaj.pdf
    • https://cdn.shopify.com/s/files/1/0429/8578/3447/files/44993178586.pdf
    • https://cdn.shopify.com/s/files/1/0436/5985/3977/files/fewazimonuritediti.pdf
    • https://cdn.shopify.com/s/files/1/0431/2688/2471/files/fanuwilazixa.pdf
    • https://cdn.shopify.com/s/files/1/0427/7446/2631/files/44503501036.pdf
    • https://cdn.shopify.com/s/files/1/0454/0645/3928/files/mojimewudinabiwogamirovo.pdf
    • https://cdn.shopify.com/s/files/1/0430/7265/1413/files/45060236852.pdf
    • https://cdn.shopify.com/s/files/1/0431/9261/5073/files/73459105101.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000758f.bin
3264aa279b1b693d22d175b02311dbdec55650a539474909911c85c39280b297
pdf-font-stream PDF embedded font (sfnt) at offset 0x758F 4940 bytes
font_01_sfnt_off00008663.bin
0ce255e0863d275b29b74af6317c0d2c9aab91072695f4122752bcbe4889db4c
pdf-font-stream PDF embedded font (sfnt) at offset 0x8663 14484 bytes