Malicious PDF — malware analysis report

Static analysis result for SHA-256 da0b006c7e9c1d77…

MALICIOUS

PDF

84.3 KB Created: 2020-08-31 00:40:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b85a5e7fad68fc38746527cbc78a51b2 SHA-1: 8965739477e06492adfc9b4f5c9e2ec95e5ecc1f SHA-256: da0b006c7e9c1d772b150c4e829fefc7de3e6510ebc53f702ffc5686dd7b173d
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link that redirects to known malicious infrastructure, as indicated by the PDF_MALICIOUS_REDIRECTOR_LINK heuristic. The document body, though heavily obfuscated, contains the URL https://ttraff.ru/wix?keyword=words+of+radiance+quotes, which is the primary IOC. The PDF_SEO_LINK_FARM heuristic suggests the PDF is part of a larger link farm designed for SEO manipulation, likely to distribute malicious content. The ML classifier also strongly indicates maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=words+of+radiance+quotes
    • https://static.usrfiles.com/ugd/eb5a6a_553c3589f1f642b598b7979d326d7d3c.pdf
    • https://static.usrfiles.com/ugd/b8c837_a0d3364034134d359eb31f41ffd4f906.pdf
    • https://static.usrfiles.com/ugd/b8c837_fbc3e5146f5d47b9bd1c8682daaed1fc.pdf
    • https://static.usrfiles.com/ugd/b8c837_d967a99cd044451d89a542901f258b04.pdf
    • https://static.usrfiles.com/ugd/d2cc1f_7ad68c2b3b2544c093b759e87033fcc5.pdf
    • https://static.usrfiles.com/ugd/a64c8c_50bcbd8fa7f6490a91e79960eba04963.pdf
    • https://static.usrfiles.com/ugd/b8c837_ad74b0de7d444d92bd1906a93270d4a2.pdf
    • https://static.usrfiles.com/ugd/d01287_6dd77f5c19e748338ff0c1c5d3d35575.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/15138334831.pdf
    • https://cdn.shopify.com/s/files/1/0432/6939/0500/files/36735456915.pdf
    • https://cdn.shopify.com/s/files/1/0432/1044/0862/files/34052256161.pdf
    • https://cdn.shopify.com/s/files/1/0434/6888/2072/files/folawelepidok.pdf
    • https://cdn.shopify.com/s/files/1/0432/3111/7467/files/agisoft_photoscan_tutorial_italiano.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010f9f.bin
9844dcf1fe2707184926d64f9f804e79ed6740172809ff0c3cfd08bd18a76d19
pdf-font-stream PDF embedded font (sfnt) at offset 0x10F9F 5120 bytes
font_01_sfnt_off00012127.bin
134c6dc2c6e64689580d6897ebbede6edbd3f6009d7c94dd9389ba2624c5444b
pdf-font-stream PDF embedded font (sfnt) at offset 0x12127 10372 bytes