Malicious PDF — malware analysis report

Static analysis result for SHA-256 d81cc85ddf0d7c73…

MALICIOUS

PDF

42.8 KB Created: 2020-09-20 00:38:43 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b5c6520bd5bf232e721f8b6608881436 SHA-1: cad90b03507fa4f3908228597c58374ddb731fd4 SHA-256: d81cc85ddf0d7c733fdb25b55fd743eecc1cab830071dd5408b495a0a1234bde
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged as malicious due to the presence of a link to a known malicious redirector. The document body contains garbled text but also includes the same URL found in the heuristic firing, suggesting it is intentionally placed. The ML classifier strongly supports the malicious verdict. No scripts were extracted, and the primary malicious behavior observed is the redirection to a potentially harmful external site.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=algia+medical+term+prefix
    • https://0ab03f93-9d99-4452-a192-a7928c768fb0.filesusr.com/ugd/61b8bf_cad600bad0c047e297d9f9e31b6ef2d6.pdf?index=true
    • https://c3d8a194-9920-4850-81f4-8b5c8c1a0266.filesusr.com/ugd/417718_b05c485c20e74f55879dcdc1fef1daec.pdf?index=true
    • https://8cb3ba07-3345-40da-9eb2-93a6d2a08a98.filesusr.com/ugd/1a94e8_db009b058c37498faeaddea5153d2dbe.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0433/7994/9718/files/schedule_template.pdf
    • https://cdn.shopify.com/s/files/1/0439/4899/8811/files/essentials_of_biology_3rd_edition.pdf
    • https://cdn.shopify.com/s/files/1/0434/6865/2697/files/weed_grow_bible_download.pdf
    • https://cdn.shopify.com/s/files/1/0457/9187/1132/files/kapijezuzijadivetunep.pdf
    • https://1ff9cdc5-e7c9-4dad-8e70-b03aa65b0cb7.filesusr.com/ugd/76de1a_23d006edd2e64aa0ac1c313da67ffbca.pdf?index=true
    • https://e6c268a2-6a13-4914-9cef-b50604b24a66.filesusr.com/ugd/3bca44_7301b3175bed4cca9f3b393d9a02efb8.pdf?index=true
    • https://628a7c3c-39e8-4bb9-bc13-982793e309b6.filesusr.com/ugd/c57cae_4fbe2481a2db4f33891b71df43787db3.pdf?index=true
    • https://c6aede1a-fc72-4553-8246-2dca3e851049.filesusr.com/ugd/6f9b04_9f04627662b0476e9a25e3d40db5a7b2.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0427/5837/3542/files/dutarepugunug.pdf
    • https://cdn.shopify.com/s/files/1/0429/5108/2143/files/disk_drill_pro_activation_code_for_windows.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005cc6.bin
b8939c48f7712e04859ed7a49097ff5367bdeb486053383f93fcd3e705a1f90d
pdf-font-stream PDF embedded font (sfnt) at offset 0x5CC6 4928 bytes
font_01_sfnt_off00006d90.bin
735795563fd79636478c2d85b43e218abce1525c96da3999ebe21f7d41baf1c7
pdf-font-stream PDF embedded font (sfnt) at offset 0x6D90 10240 bytes
font_02_sfnt_off00009085.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0x9085 4324 bytes