Malicious PDF — malware analysis report

Static analysis result for SHA-256 2040a1b86b2cc024…

MALICIOUS

PDF

40.2 KB Created: 2020-08-30 03:57:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 11812b229b9adc8e297e60b2c3ef8d5f SHA-1: ae0a98c2134360ed1f844feadeac9bac7d935dbb SHA-256: 2040a1b86b2cc02450c9e14cf7b6871a68c8c6e353e00f861fe366af368d0032
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, directing users to 'https://ttraff.ru/wix?keyword=awwa+c652+pdf'. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded links pointing to external resources, many hosted on Shopify. The ML classifier strongly supports the malicious verdict. The primary intent appears to be social engineering users into clicking the malicious link, likely for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=awwa+c652+pdf
    • https://cdn.shopify.com/s/files/1/0431/6859/6117/files/momazujodube.pdf
    • https://cdn.shopify.com/s/files/1/0432/0673/8079/files/fadolelewopazinatusekol.pdf
    • https://cdn.shopify.com/s/files/1/0436/9544/0040/files/administrative_purpose_of_performance_management_systems.pdf
    • https://cdn.shopify.com/s/files/1/0427/7318/4678/files/ingilizce_zt_anlaml_kelimeler.pdf
    • https://static.usrfiles.com/ugd/eaf48f_d7887766b5a34ae5b8f9e48d89409130.pdf
    • https://static.usrfiles.com/ugd/5926b4_de137705d264401dbb21691c4021e4f0.pdf
    • https://static.usrfiles.com/ugd/b8c837_45bbcf50317944e9922dec9d260c78bc.pdf
    • https://static.usrfiles.com/ugd/b8c837_d843a90750ae4650b03735ca80350297.pdf
    • https://static.usrfiles.com/ugd/b8c837_fbad77c40c464302a7f3396c96280163.pdf
    • https://cdn.shopify.com/s/files/1/0462/6618/7933/files/wifupezalowir.pdf
    • https://cdn.shopify.com/s/files/1/0434/7504/2457/files/39094804542.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004ba7.bin
ab53f2d5ff00fcccd739e665e79cf800e525d80a1e4b48443e862e8e911ec3cb
pdf-font-stream PDF embedded font (sfnt) at offset 0x4BA7 4660 bytes
font_01_sfnt_off00005b88.bin
1e522f7132b5839a9fc256b6ade677c1212bcf4f4608f3dae4669bde816fa51c
pdf-font-stream PDF embedded font (sfnt) at offset 0x5B88 9832 bytes
font_02_sfnt_off00007ca9.bin
1b83640b5e6d94ed72f9e8b9d7b1afba6bcb4c8604a7b755079f72d05e8a1398
pdf-font-stream PDF embedded font (sfnt) at offset 0x7CA9 2228 bytes
font_03_sfnt_off000085f3.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0x85F3 4324 bytes