Malicious PDF — malware analysis report

Static analysis result for SHA-256 e615c0f015a2b201…

MALICIOUS

PDF

65.9 KB Created: 2020-08-26 17:25:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9ca9e7ef764f4de7203503b8bdb628fc SHA-1: 4fb3c8ed2a8c4765bbdc2e07183d1cec3dc4c0bf SHA-256: e615c0f015a2b201d4d420305a3b8651a5fef708918b3dfafc41c1a38de68e28
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged by multiple critical heuristics for containing malicious redirector links and a link farm. The embedded URL points to 'ttraff.ru', which is identified as malicious infrastructure. The document body, though heavily obfuscated, contains the same malicious URL. This suggests the primary purpose is to redirect users to a potentially harmful site, likely for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=the+phantom+menace+torrent
    • http://soneze.gsavic.org/uploads/1/3/1/3/131380005/6613997.pdf
    • http://suligojov.nt-drisc.org/uploads/1/3/1/3/131398560/kunav.pdf
    • https://cdn.shopify.com/s/files/1/0433/1280/8091/files/webinigogikodufamiziva.pdf
    • https://cdn.shopify.com/s/files/1/0463/4230/8001/files/book_of_shadows_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0435/4896/7061/files/tamil_nadu_school_books_online_download.pdf
    • https://cdn.shopify.com/s/files/1/0458/5537/5513/files/destin_florida_surf_fishing_report.pdf
    • https://cdn.shopify.com/s/files/1/0431/4680/5402/files/tolotilabenejekuse.pdf
    • https://cdn.shopify.com/s/files/1/0444/1568/0679/files/kuxabikimunadug.pdf
    • https://cdn.shopify.com/s/files/1/0428/6654/0711/files/deruwuvowekemepexonipuvu.pdf
    • https://cdn.shopify.com/s/files/1/0432/3803/1518/files/54711751068.pdf
    • https://cdn.shopify.com/s/files/1/0431/5149/1233/files/janedetoguwem.pdf
    • https://cdn.shopify.com/s/files/1/0434/8067/8557/files/tuvif.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/bizem.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c648.bin
a9bf6a561f207006aa28cdf97e5816da74949e1666f5cd0e68832ca5779aa6d6
pdf-font-stream PDF embedded font (sfnt) at offset 0xC648 4912 bytes
font_01_sfnt_off0000d6cf.bin
a2df9f4b9bf2546dd177d582f1869cd6ad2204c634ebbdf8540417ad20ba4644
pdf-font-stream PDF embedded font (sfnt) at offset 0xD6CF 10708 bytes