Malicious PDF — malware analysis report

Static analysis result for SHA-256 33073c997ce99a94…

MALICIOUS

PDF

50.2 KB Created: 2020-08-09 07:55:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c9f80a0e49cea4285fc3176b271b3d0b SHA-1: f0e1eb9e77fb26bedafff5c283907b1cf0f31c55 SHA-256: 33073c997ce99a94698a81024c4d6f5ae1ab26eaae9c8dd9fe2c503fdcd00010
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains numerous links, including one pointing to a known malicious redirector at 'ttraff.ru'. The document body, though heavily obfuscated, contains this same URL, suggesting it is the primary lure. The presence of many external PDF links, some hosted on Shopify, indicates a link farm strategy to improve search engine ranking and distribute malicious content. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=amigdalitis+bacteriana+pdf+tratamiento
    • http://lekesus.olimedics.com/uploads/1/3/1/4/131482975/2806037.pdf
    • http://files.agafilmsltd.com/uploads/1/3/1/1/131164573/xevot_nabefuv_sukijipamu.pdf
    • http://files.robinsonauctionservice.com/uploads/1/3/0/9/130970022/wedenar.pdf
    • http://files.emreyaman.com/uploads/1/3/1/3/131381919/9123999.pdf
    • https://cdn.shopify.com/s/files/1/0429/4157/9420/files/34639763593.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/xizijifopaxefiz.pdf
    • https://cdn.shopify.com/s/files/1/0438/1127/4914/files/73769655397.pdf
    • https://cdn.shopify.com/s/files/1/0435/2219/5608/files/34280593251.pdf
    • https://cdn.shopify.com/s/files/1/0431/4539/6384/files/lilajajikerib.pdf
    • https://cdn.shopify.com/s/files/1/0432/8259/6004/files/2054594582.pdf
    • https://cdn.shopify.com/s/files/1/0448/6466/7810/files/the_art_book_big_ideas_simply_explained_vk.pdf
    • https://cdn.shopify.com/s/files/1/0433/1231/6584/files/70151149985.pdf
    • https://cdn.shopify.com/s/files/1/0432/7469/8902/files/wesuperabutupuruxib.pdf
    • https://cdn.shopify.com/s/files/1/0438/7880/9755/files/21748396852.pdf
    • https://cdn.shopify.com/s/files/1/0432/0978/5499/files/javepadan.pdf
    • https://cdn.shopify.com/s/files/1/0427/5834/0774/files/zigeguxaf.pdf
    • https://cdn.shopify.com/s/files/1/0430/1763/3949/files/candida_diet_recipe_book.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000081a1.bin
33ae6abd61b902481c0e4db4affb99d9d3ffaf9ccd46fc9fa806b6cca1005a54
pdf-font-stream PDF embedded font (sfnt) at offset 0x81A1 5604 bytes
font_01_sfnt_off00009493.bin
d19ab553a736261a101ba7df8a4989b9f28d2040a298a2b04ae180a3910f17cc
pdf-font-stream PDF embedded font (sfnt) at offset 0x9493 11380 bytes