Malicious PDF — malware analysis report

Static analysis result for SHA-256 2e3a30daeffaec30…

MALICIOUS

PDF

65.1 KB Created: 2020-08-01 09:46:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b11c70635984ad1b609f9d641440a9ef SHA-1: 4bda82d31ebe3ea0c57eb2c768502f5d54feb16b SHA-256: 2e3a30daeffaec30c7dbfa9cd9d2d81e4fecdb6bfe3ca9897645dbb04f79ccee
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://ttraff.ru/pify?keyword=python+bitwise+and'. Additionally, the PDF exhibits characteristics of a link farm, with numerous embedded URLs, many of which point to Shopify domains. The ML classifier also strongly flagged this PDF as malicious. The presence of these indicators suggests the document's primary purpose is to lure users to a malicious site, likely for phishing or a scam.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=python+bitwise+and
    • http://files.cookiesbykristin.com/uploads/1/3/1/4/131453028/1810e9078236569.pdf
    • http://files.digistitchcustomapparel.net/uploads/1/3/1/3/131398145/1790422.pdf
    • http://files.updatescentral.com/uploads/1/3/1/3/131384018/fotimiva_nidanu_gibuvidedavade.pdf
    • http://files.retreat4yourfeet.com/uploads/1/3/0/8/130814877/f4ee4c.pdf
    • https://cdn.shopify.com/s/files/1/0434/4712/4130/files/78258073717.pdf
    • https://cdn.shopify.com/s/files/1/0434/4535/4658/files/52845519122.pdf
    • https://cdn.shopify.com/s/files/1/0431/2023/0564/files/87915213015.pdf
    • https://cdn.shopify.com/s/files/1/0433/6871/0300/files/speech_bubble_generator.pdf
    • https://cdn.shopify.com/s/files/1/0439/4532/8808/files/2711277316.pdf
    • https://cdn.shopify.com/s/files/1/0435/7311/7091/files/genixujizuwujoliziril.pdf
    • https://cdn.shopify.com/s/files/1/0428/7548/6367/files/nidir.pdf
    • https://cdn.shopify.com/s/files/1/0429/4246/4163/files/towanekajaka.pdf
    • https://cdn.shopify.com/s/files/1/0428/1594/6911/files/47555175523.pdf
    • https://cdn.shopify.com/s/files/1/0438/4037/2896/files/49726662793.pdf
    • https://cdn.shopify.com/s/files/1/0433/6500/7509/files/nufuvexusuk.pdf
    • https://cdn.shopify.com/s/files/1/0431/0335/5034/files/94793785863.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/libutufisolefod.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000068ed.bin
dd681906fc6d579cd14902fdc46469478c0bc0341db9146bfb4566adf787a3ad
pdf-font-stream PDF embedded font (sfnt) at offset 0x68ED 16496 bytes
font_01_sfnt_off00009d65.bin
d1afa99559f5c0db706e36b4cd301a4f65eecc8398fa2bf94fbdd94f72414c50
pdf-font-stream PDF embedded font (sfnt) at offset 0x9D65 5120 bytes
font_02_sfnt_off0000aee5.bin
a173f7a30653b0c57ca9d727f9a44ff318a21a68109fc437c4665a92f69f6ea6
pdf-font-stream PDF embedded font (sfnt) at offset 0xAEE5 15876 bytes
font_03_sfnt_off0000e0a7.bin
9559dd1bd908241551916101fda3d445a26f5c4b506a1423f23393456f9d5940
pdf-font-stream PDF embedded font (sfnt) at offset 0xE0A7 16036 bytes