Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8eb395c80949b53…

MALICIOUS

PDF

43.8 KB Created: 2020-08-09 13:33:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bff69f65e7a8a0df85a37875aa5b10ac SHA-1: 6b69a8f76f62b54453cabeaf3d274d38996fefc7 SHA-256: e8eb395c80949b536cfaecc0b3d11fea40239c6d6f38c5aa6d86bec37afba2a2
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by multiple critical heuristics for containing malicious redirector links and a large number of external PDF links, indicative of SEO link farming. The primary malicious URL identified is ttraff.ru, which is known for redirecting to malicious content. While the document body contains text related to management, the embedded links suggest a deceptive purpose, likely to lure users to malicious sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=difference+between+authority+and+responsibility+in+management+pdf
    • http://files.absolute-doors.co.uk/uploads/1/3/1/6/131606526/zagodigedolesofala.pdf
    • http://files.mallorysrooftop.com/uploads/1/3/1/3/131383719/8927143.pdf
    • http://files.spencecatermusic.com/uploads/1/3/1/8/131856703/lutisarep.pdf
    • https://cdn.shopify.com/s/files/1/0437/3826/7809/files/drug_abuse_among_nigerian_youth.pdf
    • https://cdn.shopify.com/s/files/1/0431/9277/8912/files/49781334115.pdf
    • https://cdn.shopify.com/s/files/1/0431/4402/0125/files/4._625_as_a_fraction.pdf
    • https://cdn.shopify.com/s/files/1/0435/1049/7434/files/small_program.pdf
    • https://cdn.shopify.com/s/files/1/0431/8003/2160/files/47426104956.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/91428743782.pdf
    • https://cdn.shopify.com/s/files/1/0433/0392/7973/files/wasox.pdf
    • https://cdn.shopify.com/s/files/1/0434/6540/8662/files/50810422831.pdf
    • https://cdn.shopify.com/s/files/1/0428/8669/3023/files/stats_modeling_the_world.pdf
    • https://cdn.shopify.com/s/files/1/0428/8764/3303/files/second_life_redelivery.pdf
    • https://cdn.shopify.com/s/files/1/0440/3222/9541/files/matakufukenumewunixo.pdf
    • https://cdn.shopify.com/s/files/1/0427/8488/2844/files/88802690736.pdf
    • https://cdn.shopify.com/s/files/1/0432/5575/9011/files/mifixizimokubapol.pdf
    • https://cdn.shopify.com/s/files/1/0435/2134/3647/files/58096755163.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006bf3.bin
bb3f63994e8e796ed15a0f65ae103a9667923b5de4ac7ecce15872edfcb5c9ed
pdf-font-stream PDF embedded font (sfnt) at offset 0x6BF3 5904 bytes
font_01_sfnt_off00007ffd.bin
7792e55b5f61dfe3d4be139b228a534c3c723bd3e7e0806dbff08154cc001137
pdf-font-stream PDF embedded font (sfnt) at offset 0x7FFD 9796 bytes