Malicious PDF — malware analysis report

Static analysis result for SHA-256 19f7148d2b0a31cc…

MALICIOUS

PDF

43.9 KB Created: 2020-08-07 16:03:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c2d38c1f450fb6392e5b54ef5d9c3441 SHA-1: 098126ec3a4ac50cbcf61ab71141c3befb0a57e1 SHA-256: 19f7148d2b0a31ccbda974270bb7ab8575ddcdb50292517244047a8e020c902f
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, many of which point to a link farm hosted on Shopify. One of the primary links directs to a known malicious redirector at ttraff.ru, which is likely used to obscure the final malicious destination. The document body contains garbled text but includes the URL that triggered the malicious redirector heuristic, suggesting a lure to download further content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=kali+linux+tutorial+pdf+in+tamil
    • http://files.trudybellepartybox.com/uploads/1/3/1/6/131606502/tegakokekubek-kelaravutev.pdf
    • http://files.salofarm.com/uploads/1/3/1/3/131380600/pawatowugudugabim.pdf
    • http://files.shawnmichaelfiedler.com/uploads/1/3/2/6/132681985/2644071.pdf
    • http://files.discountinsulation.net/uploads/1/3/1/3/131398093/5888154ec52a02a.pdf
    • https://cdn.shopify.com/s/files/1/0430/3582/0185/files/breaking_into_wall_street_excel.pdf
    • https://cdn.shopify.com/s/files/1/0429/4115/3439/files/kokokuw.pdf
    • https://cdn.shopify.com/s/files/1/0431/5847/0813/files/824665516.pdf
    • https://cdn.shopify.com/s/files/1/0436/1283/1907/files/nutijakokimobov.pdf
    • https://cdn.shopify.com/s/files/1/0427/4513/5260/files/rizukuxujelewabonofosajad.pdf
    • https://cdn.shopify.com/s/files/1/0440/7495/9000/files/fekuduzimunibofa.pdf
    • https://cdn.shopify.com/s/files/1/0437/8794/4096/files/relao_entre_sade_e_meio_ambiente.pdf
    • https://cdn.shopify.com/s/files/1/0439/4713/1035/files/99312818221.pdf
    • https://cdn.shopify.com/s/files/1/0429/8801/1673/files/xotanuzujetob.pdf
    • https://cdn.shopify.com/s/files/1/0433/2060/6885/files/49961914981.pdf
    • https://cdn.shopify.com/s/files/1/0430/7795/9833/files/84975471011.pdf
    • https://cdn.shopify.com/s/files/1/0431/2524/4053/files/glock_19_manual.pdf
    • https://cdn.shopify.com/s/files/1/0427/8845/4559/files/nogabuxuri.pdf
    • https://cdn.shopify.com/s/files/1/0430/5181/0969/files/10520224581.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000504f.bin
d51fe570446559c85ba7b4aad121ea500519bd4a25e8b56465abddb4a2dde02e
pdf-font-stream PDF embedded font (sfnt) at offset 0x504F 5048 bytes
font_01_sfnt_off0000616e.bin
34f8d9acade7b2e100e7437976c3243dd5932ef075058ec984d43107e75db844
pdf-font-stream PDF embedded font (sfnt) at offset 0x616E 1912 bytes
font_02_sfnt_off00006aad.bin
5f3e3730fd0e1bb0d43034ce5fda4fb6f2c5eb6b57a8aebfbc71f12f918dfa67
pdf-font-stream PDF embedded font (sfnt) at offset 0x6AAD 10220 bytes
font_03_sfnt_off00008cd9.bin
ac800216f0f3ee730fcfd8224cb645483b57fad8ca3d10a0e7f9ae79b322be30
pdf-font-stream PDF embedded font (sfnt) at offset 0x8CD9 16120 bytes