Malicious PDF — malware analysis report

Static analysis result for SHA-256 de7c654cb5ac81b3…

MALICIOUS

PDF

54.7 KB Created: 2020-08-29 17:42:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a7fc88526a04a21e9a5d21ce5c03aa77 SHA-1: e87c480d476a53be7e1ab70e7810aa365fb6f7bb SHA-256: de7c654cb5ac81b3317ee426e9baaa52675abc940932853b2ec375ab3ca49e57
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.com/wix?keyword=you%2527re+so+fucking+precious'. This indicates the document's primary purpose is to redirect users to a potentially harmful site. The presence of a large number of external PDF links also suggests a link farm or SEO poisoning attempt. No scripts were extracted, but the embedded URL is the primary indicator of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=you%2527re+so+fucking+precious
    • https://static.usrfiles.com/ugd/b8c837_ca8b31c9d3a34512a3594702ac7bedb0.pdf
    • https://static.usrfiles.com/ugd/b8c837_7a17dbd8aaba487cac767d37f82ef185.pdf
    • https://static.usrfiles.com/ugd/b8c837_16e6a293a5504c0b86bfbed01fd690a4.pdf
    • https://static.usrfiles.com/ugd/b8c837_b0cbe733d7d940e59e53921b7a18ba7c.pdf
    • https://static.usrfiles.com/ugd/b8c837_f3a5991bec5e4334a69d2fa0767e093f.pdf
    • https://static.usrfiles.com/ugd/d54300_a8b8df2e83ba4ffda59ce706f3b5bd3b.pdf
    • https://static.usrfiles.com/ugd/b8c837_af9f47ef1d0647a697260afccf296c92.pdf
    • https://static.usrfiles.com/ugd/b8c837_da5208c95279464f8ddee75f4edd6cd7.pdf
    • https://static.usrfiles.com/ugd/b8c837_17f319688fd04a3e8dc02396ee577c95.pdf
    • https://cdn.shopify.com/s/files/1/0433/4760/7720/files/radians_to_degrees_python.pdf
    • https://cdn.shopify.com/s/files/1/0437/2342/3912/files/lulog.pdf
    • https://cdn.shopify.com/s/files/1/0435/5748/6753/files/dental_anatomy_handbook.pdf
    • https://cdn.shopify.com/s/files/1/0435/9513/7181/files/sevos.pdf
    • https://cdn.shopify.com/s/files/1/0434/4525/6352/files/dawapajukawagutage.pdf
    • https://cdn.shopify.com/s/files/1/0430/6999/7207/files/nifowakimuzof.pdf
    • https://cdn.shopify.com/s/files/1/0439/2475/0491/files/14379733881.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005788.bin
2ce5a7286efefc5aae27ce1c31b3347e159d00bd30cf97f509a0b7f7d49caffb
pdf-font-stream PDF embedded font (sfnt) at offset 0x5788 6440 bytes
font_01_sfnt_off0000677d.bin
1a2784e95b5788f6e04a7d4ff37c2bf1e2a68d8442af98e9bbfe00ad50a6d79d
pdf-font-stream PDF embedded font (sfnt) at offset 0x677D 4804 bytes
font_02_sfnt_off000077e3.bin
de2e451141f2db4210e9000deb63e0c7732a1cbb11d0de31c5d1a8f45b7ee5f1
pdf-font-stream PDF embedded font (sfnt) at offset 0x77E3 3000 bytes
font_03_sfnt_off0000845f.bin
a889866f01be8db9c526798a3d78f2a176bd9ca499ddc0516d54ae79e11651b3
pdf-font-stream PDF embedded font (sfnt) at offset 0x845F 10228 bytes
font_04_sfnt_off0000a780.bin
2fc793194720fdb270df9d08fc2262a7b7355322cfb0e0addc9ff1516ae71766
pdf-font-stream PDF embedded font (sfnt) at offset 0xA780 16728 bytes
font_05_sfnt_off0000be1f.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0xBE1F 4324 bytes