Malicious PDF — malware analysis report

Static analysis result for SHA-256 ea7e595ff643e8a4…

MALICIOUS

PDF

64.6 KB Created: 2020-08-04 10:56:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b94637b460724a6213eeacb64dea3738 SHA-1: 0c7d95098ff6ea93fa9ca4eb0e8886f1405fff7d SHA-256: ea7e595ff643e8a43d80a3dbb159b52efd911dc5dca3c4b562b9a0eafae48516
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a high number of external links, many pointing to what appears to be a link farm designed for SEO manipulation. One critical heuristic identified a link to a known malicious redirector, ttraff.cc, which is used to obscure the final destination. The document body, though heavily obfuscated, contains the URL that triggered the malicious redirector heuristic. This suggests the PDF is part of a campaign to drive traffic to malicious sites, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=buffer+solution+definition+pdf
    • http://files.helenhenryraro.com/uploads/1/3/1/4/131438843/ba4ab2a0c8475a.pdf
    • http://files.after5designs.ca/uploads/1/3/2/7/132740598/rudob.pdf
    • http://files.livingatthedistillery.com/uploads/1/3/2/6/132681884/moletobazan.pdf
    • http://files.helenhenryraro.com/uploads/1/3/1/4/131438843/b
    • https://cdn.shopify.com/s/files/1/0445/8453/4180/files/automatic_capsule_filling_machine_manual.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/99231100330.pdf
    • https://cdn.shopify.com/s/files/1/0430/9683/4212/files/97803421512.pdf
    • https://cdn.shopify.com/s/files/1/0429/0795/9452/files/93619201017.pdf
    • https://cdn.shopify.com/s/files/1/0435/4503/4911/files/tirefujevuvitalupuxos.pdf
    • https://cdn.shopify.com/s/files/1/0433/4590/3774/files/zigexukozedevelukig.pdf
    • https://cdn.shopify.com/s/files/1/0438/1242/1789/files/41438605163.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/ligumugazawebamupewav.pdf
    • https://cdn.shopify.com/s/files/1/0438/6711/1584/files/capes_results_ucsd.pdf
    • https://cdn.shopify.com/s/files/1/0434/1058/7800/files/92754704092.pdf
    • https://cdn.shopify.com/s/files/1/0439/1705/0008/files/mifuvoluxetula.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/64989875230.pdf
    • https://cdn.shopify.com/s/files/1/0430/9942/2881/files/toluvulodiwurabujutekib.pdf
    • https://cdn.shopify.com/s/files/1/0427/7560/9510/files/51486040825.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009e75.bin
c4cf564cb47a924f6470d060460034c686d4826ef55a940d0da66b731f44192a
pdf-font-stream PDF embedded font (sfnt) at offset 0x9E75 4876 bytes
font_01_sfnt_off0000af20.bin
f7de596b44c0a1e2d3ff903e11136c8c42f487c8c240db2ec9fa80f8814b4b8e
pdf-font-stream PDF embedded font (sfnt) at offset 0xAF20 15656 bytes
font_02_sfnt_off0000df73.bin
d784da7d5db94080844d7b8f4a2defffee6795b160fe1c6fe222e491b1d25c7c
pdf-font-stream PDF embedded font (sfnt) at offset 0xDF73 16196 bytes