Malicious PDF — malware analysis report

Static analysis result for SHA-256 43f80916bab9f940…

MALICIOUS

PDF

34.4 KB Created: 2020-09-01 00:32:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 31c982075f869b84a714c25144c51e97 SHA-1: 782cb8e1d9235595c881e56403d08ef1a7c6adb1 SHA-256: 43f80916bab9f94030f7ffd2fef18fe3dfc73f2a9599c48e070d452471fbb27d
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a heuristic firing for a malicious redirector link, pointing to 'ttraff.ru'. It also exhibits a PDF link farm behavior, embedding numerous links to external PDFs, with the primary one being 'cdn.shopify.com/s/files/1/0433/5930/5880/files/nipatazugo.pdf'. The document body, though heavily obfuscated, contains the malicious URL and a benign-looking financial report title, suggesting a lure to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=adhi+karya+financial+report
    • https://cdn.shopify.com/s/files/1/0433/5930/5880/files/nipatazugo.pdf
    • https://cdn.shopify.com/s/files/1/0439/3366/3400/files/gastrointestinal_system_anatomy.pdf
    • https://cdn.shopify.com/s/files/1/0435/1167/7083/files/53418123495.pdf
    • https://cdn.shopify.com/s/files/1/0459/1756/9173/files/iron_man_1994_episode_guide.pdf
    • https://cdn.shopify.com/s/files/1/0428/5235/2159/files/43986017283.pdf
    • https://cdn.shopify.com/s/files/1/0437/1959/0056/files/86350205648.pdf
    • https://cdn.shopify.com/s/files/1/0433/8037/5708/files/wondershare_editor_ocr_plugin.pdf
    • https://static.usrfiles.com/ugd/04e6f9_a38dd6a8ca7642fe8d19911f9c979281.pdf
    • https://static.usrfiles.com/ugd/b8c837_685c5de96c4c4fb7b9e312da8da0a627.pdf
    • https://static.usrfiles.com/ugd/b8c837_1e31b88086104db29415b86c1fade428.pdf
    • https://static.usrfiles.com/ugd/834936_d6b1c1d03b404fe3b85224e4fbabde38.pdf
    • https://static.usrfiles.com/ugd/a2d007_0907422515844c8696f0b60b7f702654.pdf
    • https://static.usrfiles.com/ugd/ac51ce_874b61c9329b40d3891670aa5da64354.pdf
    • https://static.usrfiles.com/ugd/19ce5d_f010d4a5e9b3423b8dc2705e81654fe8.pdf
    • https://static.usrfiles.com/ugd/c0b427_e4e3eaf5ebe245efa85bff0269104392.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000049b8.bin
241de0df0a317c3b696d7dd96698682c08d16dc6d2754f5b8039be5af36d732c
pdf-font-stream PDF embedded font (sfnt) at offset 0x49B8 5220 bytes
font_01_sfnt_off00005b83.bin
5911fa10d6288c9a44754b080e66ef50e2da0cb64adeb9a7f586b9956e49e546
pdf-font-stream PDF embedded font (sfnt) at offset 0x5B83 10008 bytes