Malicious PDF — malware analysis report

Static analysis result for SHA-256 fa5c3615e3a10a5a…

MALICIOUS

PDF

64.8 KB Created: 2020-08-20 09:53:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a6982007c90fdf54e7df6396e53e5f77 SHA-1: 3eed59509cc0deb7f9e8f6d5a0c656ea5e3beb68 SHA-256: fa5c3615e3a10a5a98421402fecd0028b4576cfd260aecbe6836b451adece9d3
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF was flagged for containing a malicious redirector link and a link farm. The primary malicious URL, 'https://ttraff.ru/pify?keyword=2009+holden+barina+owners+manual', is likely used to funnel victims to a phishing or malware site. The document body, though heavily obfuscated, contains references to the URL, reinforcing its role in the attack. The presence of numerous links to external PDFs, many hosted on Shopify, suggests a tactic to obscure the ultimate destination or to create a large surface area for SEO-based lures.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=2009+holden+barina+owners+manual
    • http://files.rootedaltarministries.org/uploads/1/3/0/9/130969628/7e6407cc890.pdf
    • https://cdn.shopify.com/s/files/1/0428/4219/4083/files/gunoloxodenepob.pdf
    • https://cdn.shopify.com/s/files/1/0437/7323/1258/files/18614228703.pdf
    • https://cdn.shopify.com/s/files/1/0430/5174/5442/files/1183718828.pdf
    • https://cdn.shopify.com/s/files/1/0435/9792/2461/files/money_is_the_answer_to_everything_book.pdf
    • https://cdn.shopify.com/s/files/1/0427/3415/7991/files/nozibekugusiwogenon.pdf
    • https://cdn.shopify.com/s/files/1/0427/6014/3014/files/fofadegosabomevegunebani.pdf
    • https://cdn.shopify.com/s/files/1/0428/2925/0719/files/special_occasion_speech_outline.pdf
    • https://cdn.shopify.com/s/files/1/0434/5361/2182/files/37083194507.pdf
    • https://cdn.shopify.com/s/files/1/0447/2619/0234/files/dark_souls_2_blacksmith_key.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000bebc.bin
8073a069abde2606d0c1f1ec0a01a3ecd61716bc27b508a61255a92c75d42b91
pdf-font-stream PDF embedded font (sfnt) at offset 0xBEBC 5632 bytes
font_01_sfnt_off0000d1ab.bin
37304c94c526eedc80b248a7371b037f9586ac21597424c062e902fe2693ad20
pdf-font-stream PDF embedded font (sfnt) at offset 0xD1AB 10756 bytes