Malicious PDF — malware analysis report

Static analysis result for SHA-256 f81fad11c95f32da…

MALICIOUS

PDF

93.5 KB Created: 2020-07-26 12:28:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: dd0b3c207a07a99b2adc59f1579ea7fa SHA-1: c850eccd2a71b62a049d9cefd10c6ea583f5d373 SHA-256: f81fad11c95f32dac4f0293192f53bef76218d627c84ae0121e5313711eda8f2
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'ttraff.ru'. Additionally, it features a PDF link farm with numerous external links, many hosted on Shopify. The ML classifier also strongly flagged this PDF as malicious. The embedded content appears to be obfuscated text, but the primary malicious activity is the redirection to the malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=lagu+btob+missing+you+full+album
    • http://files.wildcrafttasmania.com/uploads/1/3/1/4/131409677/lodadapeb.pdf
    • http://files.tommccall.org/uploads/1/3/1/8/131872015/1706379.pdf
    • http://files.renzoeats.com/uploads/1/3/1/6/131636654/9582390.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/riwemabosemuridaredexe.pdf
    • https://cdn.shopify.com/s/files/1/0433/8181/7505/files/bofagelugorejav.pdf
    • https://cdn.shopify.com/s/files/1/0431/0374/8263/files/nidon.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/87745409623.pdf
    • https://cdn.shopify.com/s/files/1/0427/8134/3900/files/lerokanodisorigus.pdf
    • https://cdn.shopify.com/s/files/1/0431/0332/2261/files/lefanobuwaxuriwepolu.pdf
    • https://cdn.shopify.com/s/files/1/0433/6081/3208/files/xotikaseribijikaxulag.pdf
    • https://cdn.shopify.com/s/files/1/0432/2341/6987/files/39053240248.pdf
    • https://cdn.shopify.com/s/files/1/0433/9384/3358/files/39422965942.pdf
    • https://cdn.shopify.com/s/files/1/0429/2568/6951/files/63632876255.pdf
    • https://cdn.shopify.com/s/files/1/0431/6859/6123/files/67963542822.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b15d.bin
52971924cad43fe9f52ea1e22a528713142e7d3d32840adf4945ddc4c877b663
pdf-font-stream PDF embedded font (sfnt) at offset 0xB15D 38824 bytes
font_01_sfnt_off00012309.bin
4115331e9edb020f4160db45e0928b3ea21a55567961e0c9d986e32f6a59732c
pdf-font-stream PDF embedded font (sfnt) at offset 0x12309 4940 bytes
font_02_sfnt_off000133cc.bin
676e80ede44a506b0112928387b7656dc473196899420b21b878dc1cf0d9e97c
pdf-font-stream PDF embedded font (sfnt) at offset 0x133CC 17048 bytes