Malicious PDF — malware analysis report

Static analysis result for SHA-256 3a852493d78e0e79…

MALICIOUS

PDF

97.8 KB Created: 2020-08-09 03:10:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a81057af93ea4345bbfc4d966ba12d33 SHA-1: 50b7d1ff0dcfcc941ebcc681096b1f2c80cc9df9 SHA-256: 3a852493d78e0e79b2e98c938fdc69c94bb44c684bb917b331daa5ea1ec2c538
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, many of which point to a redirector service (ttraff.cc). The document body, though heavily obfuscated, contains the URL that is also present in the heuristics. This suggests the primary goal is to redirect the user to malicious infrastructure. No scripts were extracted, limiting the ability to determine further payload delivery or persistence mechanisms.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=pdf+of+multivariate+normal+distribution
    • http://files.rone.studio/uploads/1/3/1/3/131379266/gopijiwupevutekifari.pdf
    • http://fifage.lmctotherescue.com/uploads/1/3/1/1/131163599/givozupimexejasatu.pdf
    • http://fonesapi.whogivesascrapcolorado.com/uploads/1/3/1/3/131383664/7894999.pdf
    • http://files.drtaoka.com/uploads/1/3/1/1/131164393/7087916.pdf
    • https://cdn.shopify.com/s/files/1/0434/2756/1634/files/the_antlered_ship.pdf
    • https://cdn.shopify.com/s/files/1/0431/5840/5274/files/air_conditioner_cycle_diagram.pdf
    • https://cdn.shopify.com/s/files/1/0430/8910/0951/files/18852544513.pdf
    • https://cdn.shopify.com/s/files/1/0440/2118/6718/files/calentadores_solares_caseros.pdf
    • https://cdn.shopify.com/s/files/1/0430/5308/8919/files/list_of_b_pharmacy_colleges_in_maharashtra.pdf
    • https://cdn.shopify.com/s/files/1/0440/4484/5206/files/rename_dataframe_column_r.pdf
    • https://cdn.shopify.com/s/files/1/0435/3641/6936/files/bapajemumirire.pdf
    • https://cdn.shopify.com/s/files/1/0433/4921/3349/files/byte_to_string.pdf
    • https://cdn.shopify.com/s/files/1/0435/2881/4760/files/pokifodarigazanexe.pdf
    • https://cdn.shopify.com/s/files/1/0428/2561/3475/files/advantages_and_disadvantages_of_direct_marketing.pdf
    • https://cdn.shopify.com/s/files/1/0428/9301/7247/files/32069534527.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000116fd.bin
9d10aef151b2d245a1775c8b4dc05aa3ebcd79088db8f2b7094dcdc1ebe3703a
pdf-font-stream PDF embedded font (sfnt) at offset 0x116FD 5252 bytes
font_01_sfnt_off000128c7.bin
7fe846e3b54cea8af55457e01755a2a6d71bc509693a96236d25879f08fc10aa
pdf-font-stream PDF embedded font (sfnt) at offset 0x128C7 17996 bytes
font_02_sfnt_off000161d8.bin
9ff8a9de27d3f29295606172d5af35b85ccaa9c0a9212ad4ccb10132021197d3
pdf-font-stream PDF embedded font (sfnt) at offset 0x161D8 16744 bytes