Malicious PDF — malware analysis report

Static analysis result for SHA-256 35f6a4929131bde3…

MALICIOUS

PDF

63.5 KB Created: 2020-08-17 11:46:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2f4eb23adb378a3bcb472b8395239717 SHA-1: 6533f40e7106786d4e01da01d0adbffdbb8ea5a9 SHA-256: 35f6a4929131bde36d490287fcb96bba6198998e0f64e8419e613cf65835b455
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.ru'. Additionally, it exhibits a PDF link farm heuristic, with numerous links to Shopify-hosted PDFs, suggesting an attempt to obscure the malicious destination or distribute further content. The ML classifier also strongly indicated maliciousness. The primary malicious IOC is the redirector URL, which likely leads to a phishing page or malware download.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=hasyiyah+al+baijuri+pdf
    • http://lavevatu.mydhfastmandat.com/uploads/1/3/2/7/132740494/8511117.pdf
    • https://cdn.shopify.com/s/files/1/0450/8450/8325/files/public_health_policy_formulation.pdf
    • https://cdn.shopify.com/s/files/1/0430/9201/7305/files/76881995823.pdf
    • https://cdn.shopify.com/s/files/1/0436/3524/5214/files/40719444159.pdf
    • https://cdn.shopify.com/s/files/1/0431/2779/9969/files/sum_in_google_sheets.pdf
    • https://cdn.shopify.com/s/files/1/0432/8400/5032/files/zamorovumifewuwotov.pdf
    • https://cdn.shopify.com/s/files/1/0440/1076/6486/files/best_tablet_for_viewing_drawings.pdf
    • https://cdn.shopify.com/s/files/1/0444/5673/8983/files/vujogadajabudi.pdf
    • https://cdn.shopify.com/s/files/1/0427/4041/6678/files/toruxozevasuxo.pdf
    • https://cdn.shopify.com/s/files/1/0436/7400/9753/files/anesthesia_made_easy_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0433/1359/4526/files/platinum_mathematics_grade_7_teacher_s_guide_download.pdf
    • https://cdn.shopify.com/s/files/1/0437/9613/6098/files/you_spin_my_head_right_round_lyrics.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off0000cb7d.bin
6e015dc5dfe436398e03a6e74eb87d1d66efb7d3515cf8e7819a8c0b105da954
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xCB7D 21384 bytes
font_00_sfnt_off0000874f.bin
b6779bfa84e87b669024919e7c41be07b2870b25c654e2b8a588dd77eb71067b
pdf-font-stream PDF embedded font (sfnt) at offset 0x874F 2948 bytes
font_01_sfnt_off000091d0.bin
2b1ff666a6de11d5d93660c3007c8726f28338e66fc2ef648092b1a6890f54a9
pdf-font-stream PDF embedded font (sfnt) at offset 0x91D0 5408 bytes
font_02_sfnt_off0000a42a.bin
63673dd285183f5ba2bdc51668f9a478138fc707938881ab8ba18ec154b1573d
pdf-font-stream PDF embedded font (sfnt) at offset 0xA42A 11860 bytes