Malicious PDF — malware analysis report

Static analysis result for SHA-256 e799bf62f37647cd…

MALICIOUS

PDF

49.9 KB Created: 2020-08-31 21:55:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: aab588ee0173807041e1b8ca970747ef SHA-1: c1d5540e74f32c5f3d2b1b6f773b2cc4d5b1b28b SHA-256: e799bf62f37647cd8cc0255f170c9c2631af039941068aa8051723faafe5dc17
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged for containing a malicious redirector link and a large number of external links, suggesting a link farm. The embedded URL 'https://ttraff.club/pify?keyword=4health+dog+food+feeding+guide' is identified as a malicious redirector. The document body, though heavily obfuscated, contains references to this URL, reinforcing its role in the attack. The primary goal appears to be directing users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/pify?keyword=4health+dog+food+feeding+guide
    • https://static.usrfiles.com/ugd/b8c837_22813a1d775f470e99dea0f87da2c60b.pdf
    • https://static.usrfiles.com/ugd/913720_015842c5955c449287f40ac5b5727571.pdf
    • https://static.usrfiles.com/ugd/9cc572_0f140420f9704278b3784f70b6e7c42a.pdf
    • https://static.usrfiles.com/ugd/66c878_998138b599c140a6b4061d9395efaa0a.pdf
    • https://static.usrfiles.com/ugd/6c032c_3fce2b1dce47440294a430a20e10e61f.pdf
    • https://cdn.shopify.com/s/files/1/0430/3690/1527/files/33092583535.pdf
    • https://static.usrfiles.com/ugd/b8c837_233d63fd43384f64a6583dfb153e8502.pdf
    • https://static.usrfiles.com/ugd/0df15e_91ea65ec513d4cf9bee342d4071b48f7.pdf
    • https://cdn.shopify.com/s/files/1/0429/8817/5513/files/lijupig.pdf
    • https://cdn.shopify.com/s/files/1/0434/6275/4461/files/mawixowi.pdf
    • https://cdn.shopify.com/s/files/1/0433/8676/5475/files/wagas.pdf
    • https://cdn.shopify.com/s/files/1/0435/0912/1184/files/pambansang_bayani_ng_pilipinas.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000854a.bin
8053745df23828d255d27bcc7a17b1660b8e1caecb52af4655f50d23097bb1fa
pdf-font-stream PDF embedded font (sfnt) at offset 0x854A 4888 bytes
font_01_sfnt_off000095f5.bin
b2e25ad569d41353ad615b52dfa517b442f90713e8f37d268d2c6b2d2d9c5e2f
pdf-font-stream PDF embedded font (sfnt) at offset 0x95F5 11092 bytes