Malicious PDF — malware analysis report

Static analysis result for SHA-256 e26161baeb35d225…

MALICIOUS

PDF

39.0 KB Created: 2020-09-05 14:09:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a1d1ed0a4395a317de67c54110e22086 SHA-1: 84d96a3e96114fcb36f7b03817230d8e8d9ebc35 SHA-256: e26161baeb35d225b42b215db46b629d77af5df4fa1e5207b5e7fcfc7158f0ee
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by multiple critical heuristics for containing malicious redirector links and a large link farm. The embedded URL `https://ttraff.link/wix?keyword=cheryl+cole+fight+for+this+love` is identified as a malicious redirector. Additionally, the document contains numerous links pointing to `cdn.shopify.com`, suggesting an attempt to manipulate search engine results or distribute further malicious content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=cheryl+cole+fight+for+this+love
    • https://cdn.shopify.com/s/files/1/0429/2352/4259/files/informal_letter_writing_topics_for_grade_10.pdf
    • https://cdn.shopify.com/s/files/1/0434/7261/7637/files/fotanawuzajorigirak.pdf
    • https://cdn.shopify.com/s/files/1/0432/9222/9797/files/32673388495.pdf
    • https://cdn.shopify.com/s/files/1/0429/9345/1159/files/medical_laboratory_safety_manual.pdf
    • https://cdn.shopify.com/s/files/1/0431/4457/7178/files/xazozisebamewabedawo.pdf
    • https://cdn.shopify.com/s/files/1/0430/4617/4877/files/38520491737.pdf
    • https://cdn.shopify.com/s/files/1/0432/5651/2676/files/miwek.pdf
    • https://cdn.shopify.com/s/files/1/0428/8184/3356/files/mp3_monkey_downloader.pdf
    • https://cdn.shopify.com/s/files/1/0430/9752/2329/files/tetikajodugidekixi.pdf
    • https://static.usrfiles.com/ugd/c3548c_804248b4b8e94307920c6ab877a80dc5.pdf
    • https://static.usrfiles.com/ugd/3e5d97_aad8e182fb484c038996fe3a0b74825b.pdf
    • https://static.usrfiles.com/ugd/b8c837_5b0760ebcf8242cf9a594d4b66f2709a.pdf
    • https://static.usrfiles.com/ugd/b58d21_7ce0eb0017d84ed79065d534bb47d0af.pdf
    • https://static.usrfiles.com/ugd/5cf23b_0b299fc280f14595a3c9fce6c0e44c98.pdf
    • https://cdn.shopify.com/s/files/1/0432/9255/7462/files/53010402578.pdf
    • https://cdn.shopify.com/s/files/1/0437/7300/1877/files/noguvodimizuwupelo.pdf
    • https://cdn.shopify.com/s/files/1/0430/5921/6537/files/coordinate_conjunction_exercise.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005642.bin
3db29fe010d37ee417a61f2a5bfb1c9a68620453e07bb502d2ab6cdee31b6813
pdf-font-stream PDF embedded font (sfnt) at offset 0x5642 5000 bytes
font_01_sfnt_off00006758.bin
f1318353753693c4b02a5e8d4d84c7609837de4ed630a1a2e9764725f6864b79
pdf-font-stream PDF embedded font (sfnt) at offset 0x6758 12568 bytes