Malicious PDF — malware analysis report

Static analysis result for SHA-256 2eb863fdc86b9388…

MALICIOUS

PDF

44.2 KB Created: 2020-08-20 10:38:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f33993783c1cdc95dd0fe42d64806899 SHA-1: c4bb1c699b8253fa0ed1cc3d3852f45597de4e3e SHA-256: 2eb863fdc86b938825a07cf32e3973891d8021797db2d0a6efcde460bf35340f
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, which is also present in the document body. This link, 'https://ttraff.cc/pify?keyword=papa%2527+s+cheeseria+to+go+free', is designed to lure users by promising a free game download. The document also exhibits characteristics of a link farm, with numerous embedded URLs, many pointing to Shopify. The ML classifier strongly flagged this PDF as malicious. No scripts were extracted, but the presence of the malicious redirector is sufficient evidence of a phishing or redirection attack.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=papa%2527+s+cheeseria+to+go+free
    • http://files.dejagerlimousin.com/uploads/1/3/2/6/132695258/kojafu.pdf
    • https://cdn.shopify.com/s/files/1/0428/4517/5971/files/acer_aspire_one_ao756_manual.pdf
    • https://cdn.shopify.com/s/files/1/0432/2151/6445/files/antiemetics_chemotherapy_guidelines.pdf
    • https://cdn.shopify.com/s/files/1/0430/3273/9989/files/kaldarshak_calendar_2020_download.pdf
    • https://cdn.shopify.com/s/files/1/0434/1900/9189/files/paradise_lost_book_ix.pdf
    • https://cdn.shopify.com/s/files/1/0454/2434/5244/files/rukaviresudina.pdf
    • https://cdn.shopify.com/s/files/1/0431/0866/3456/files/29227201013.pdf
    • https://cdn.shopify.com/s/files/1/0428/5045/1623/files/65758125919.pdf
    • https://cdn.shopify.com/s/files/1/0435/5335/7985/files/ligik.pdf
    • https://cdn.shopify.com/s/files/1/0431/5889/6802/files/2380780655.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/49186839350.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006d3e.bin
253efc198511eea6f7cd742a8a88ff5aec03332ad41e6b18f5a7b674678cf330
pdf-font-stream PDF embedded font (sfnt) at offset 0x6D3E 5280 bytes
font_01_sfnt_off00007f35.bin
494c250e0d81037a58ecda60fba3cbce1e789a404b4d79fba7da760aa4de50da
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F35 10428 bytes