Malicious PDF — malware analysis report

Static analysis result for SHA-256 ede4fe4928faf8f6…

MALICIOUS

PDF

52.6 KB Created: 2020-07-24 17:14:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: acf8e70dbd609bd5545eae21c3ffbb7a SHA-1: 1765bdd1864af3d03b2598463f270f29e42a3df9 SHA-256: ede4fe4928faf8f681f7ef81a6fab210a8525cf472e3a346411382f2cdd6bb26
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, with a critical heuristic firing for PDF_MALICIOUS_REDIRECTOR_LINK and PDF_SEO_LINK_FARM. The primary redirector URL is https://ttraff.ru/pify?keyword=ism+audio+songs++com+telugu, which is likely used to distribute further malicious content or phishing pages. The document body is heavily obfuscated and appears to be junk data, reinforcing the idea that the document's sole purpose is to host these links.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=ism+audio+songs++com+telugu
    • http://files.sinkpong.pub/uploads/1/3/1/0/131070459/vekugoruju-lumevutavejo.pdf
    • http://files.kingvan.com.au/uploads/1/3/0/9/130969188/6356949.pdf
    • http://files.innovationsbuildingservices.com/uploads/1/3/1/4/131438150/827431.pdf
    • http://files.upsidedownambo.com/uploads/1/3/1/0/131071043/bududuposedasaf.pdf
    • https://cdn.shopify.com/s/files/1/0429/5252/3929/files/50934105906.pdf
    • https://cdn.shopify.com/s/files/1/0428/8462/8633/files/wedixop.pdf
    • https://cdn.shopify.com/s/files/1/0434/3404/9703/files/15251999958.pdf
    • https://cdn.shopify.com/s/files/1/0433/7667/2918/files/61204147852.pdf
    • https://cdn.shopify.com/s/files/1/0434/8605/2504/files/25194476070.pdf
    • https://cdn.shopify.com/s/files/1/0429/7257/7946/files/21983505337.pdf
    • https://cdn.shopify.com/s/files/1/0429/7264/3491/files/7068720282.pdf
    • https://cdn.shopify.com/s/files/1/0428/2905/4118/files/disemiguforu.pdf
    • https://cdn.shopify.com/s/files/1/0431/6705/6028/files/45692957372.pdf
    • https://cdn.shopify.com/s/files/1/0431/0063/5290/files/ruliwim.pdf
    • https://cdn.shopify.com/s/files/1/0428/7247/1715/files/37495457480.pdf
    • https://cdn.shopify.com/s/files/1/0433/6726/8517/files/velutasun.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/sekokejeninidifowabofu.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/30106301206.pdf
    • https://cdn.shopify.com/s/files/1/0434/0583/6438/files/48800900296.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000883a.bin
ddb1b9b2ffa55b131ed8a30aab32f62860038869641b8a821b9b81dd2c1cc6ac
pdf-font-stream PDF embedded font (sfnt) at offset 0x883A 4984 bytes
font_01_sfnt_off0000990b.bin
f7431cb6bcad277aede03fe7038447abe91cac4ddb191e83769bd4719a30c0b5
pdf-font-stream PDF embedded font (sfnt) at offset 0x990B 14200 bytes