Malicious PDF — malware analysis report

Static analysis result for SHA-256 dd07312fac58e5ba…

MALICIOUS

PDF

77.3 KB Created: 2020-08-31 12:14:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ac678c37395eaa75a88f73714d2607ea SHA-1: 53a20c9c5af7790834e2b28b3b1ba8c8dd20ec02 SHA-256: dd07312fac58e5baebe99dc68f8d0a16c569eeed1c17307587000fcd8d91bbde
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document was flagged by multiple critical heuristics for containing malicious redirector links and a large link farm. The primary malicious URL identified is ttraff.ru, which is used to redirect to other URLs, including a Shopify domain. The document body contains garbled text but includes the primary malicious URL and several other Shopify URLs, suggesting a lure to download further content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=pokemon+jirachi+wish+maker+movie+in
    • https://cdn.shopify.com/s/files/1/0437/7713/0647/files/full_auto_1022.pdf
    • https://cdn.shopify.com/s/files/1/0433/4875/4600/files/41849411974.pdf
    • https://cdn.shopify.com/s/files/1/0434/7016/0032/files/jvvnl_junior_accountant_syllabus.pdf
    • https://cdn.shopify.com/s/files/1/0437/0304/2216/files/34853392510.pdf
    • https://cdn.shopify.com/s/files/1/0431/1931/3053/files/complete_interview_answer_guide.pdf
    • https://cdn.shopify.com/s/files/1/0431/6512/2720/files/se_hinton_the_outsiders_cast.pdf
    • https://cdn.shopify.com/s/files/1/0429/9345/1159/files/46288559090.pdf
    • https://cdn.shopify.com/s/files/1/0434/6295/1062/files/rspec_vs_cucumber.pdf
    • https://cdn.shopify.com/s/files/1/0434/1753/4629/files/disadvantages_of_centralized_information_system.pdf
    • https://cdn.shopify.com/s/files/1/0431/7731/2411/files/tisolupebuxagazologef.pdf
    • https://cdn.shopify.com/s/files/1/0437/7765/4935/files/for_the_damaged_coda_piano_sheet_music_free.pdf
    • https://cdn.shopify.com/s/files/1/0440/0267/2798/files/48373156353.pdf
    • https://cdn.shopify.com/s/files/1/0431/6784/2459/files/fabixazifuvusovitoromupig.pdf
    • https://cdn.shopify.com/s/files/1/0437/7663/9127/files/aqua_barbie_remix_song.pdf
    • https://cdn.shopify.com/s/files/1/0432/4858/2820/files/wurexeduk.pdf
    • https://cdn.shopify.com/s/files/1/0429/7401/9740/files/gomaburiwilumemizexuv.pdf
    • https://cdn.shopify.com/s/files/1/0434/4109/4817/files/39580859456.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off0000d599.bin
278d8e8cc700b3b29e783c3478a90cc410bf0135e8e7fff6d1a00679bd1b2d47
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xD599 4336 bytes
font_00_sfnt_off00009937.bin
c638d0604bf6393cda128c430ed243a0e950e0368dc70fd6a8f5ada88095c12e
pdf-font-stream PDF embedded font (sfnt) at offset 0x9937 12892 bytes
font_01_sfnt_off0000c3a9.bin
5125a0e67bdb61806abc9b49bad4330a7f0524731d3cf579775b7c5566cc678e
pdf-font-stream PDF embedded font (sfnt) at offset 0xC3A9 5300 bytes
font_03_sfnt_off0000e4fd.bin
74f755f8586a8a9d05bdfb9fbc89645a0458be045182b60b1c095a591c820c0d
pdf-font-stream PDF embedded font (sfnt) at offset 0xE4FD 3196 bytes
font_04_sfnt_off0000f21c.bin
ccb646ec8074245d31f99108a7d067ac7d99a5116b82971e27c6a1e6e012a07e
pdf-font-stream PDF embedded font (sfnt) at offset 0xF21C 11776 bytes
font_05_sfnt_off000119af.bin
150fc8fa826a430bdef8d1d17d5eba602f011cedfbbeedea7abae115439d3ee4
pdf-font-stream PDF embedded font (sfnt) at offset 0x119AF 3268 bytes