Malicious PDF — malware analysis report

Static analysis result for SHA-256 527dcadd59663f8f…

MALICIOUS

PDF

48.3 KB Created: 2020-08-02 16:39:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a14901c9b46984c537a4496496ab5b44 SHA-1: d23813a27775631f7a247e7cd7cf8e3efc9514e0 SHA-256: 527dcadd59663f8f720cb248aada3933e81ffc5a7189529a6eb08cbc6d3a56b4
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.ru/pify?keyword=levi+league+of+legends'. This URL is likely part of a phishing or scam campaign, attempting to lure users with a seemingly relevant keyword. The document also exhibits characteristics of a link farm, with numerous embedded URLs, many pointing to Shopify domains, suggesting an attempt to obscure the malicious destination or distribute content. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=levi+league+of+legends
    • http://files.uabiochemistryclub.com/uploads/1/3/1/4/131438013/4891274.pdf
    • http://files.highgrundoncottages.com/uploads/1/3/1/0/131071249/4f9a6b.pdf
    • http://files.joanadler.com/uploads/1/3/1/1/131163601/dutelaroboluf.pdf
    • https://cdn.shopify.com/s/files/1/0433/8951/7973/files/bopajadasuwenewezuxon.pdf
    • https://cdn.shopify.com/s/files/1/0427/7462/6470/files/64539844712.pdf
    • https://cdn.shopify.com/s/files/1/0437/4547/6762/files/rixalowotegisimomimujebi.pdf
    • https://cdn.shopify.com/s/files/1/0432/8439/8236/files/48784623615.pdf
    • https://cdn.shopify.com/s/files/1/0432/5530/0249/files/75154349034.pdf
    • https://cdn.shopify.com/s/files/1/0428/3957/2643/files/46833423195.pdf
    • https://cdn.shopify.com/s/files/1/0433/5042/5750/files/96010457324.pdf
    • https://cdn.shopify.com/s/files/1/0437/4154/4599/files/changeling_the_lost_contracts.pdf
    • https://cdn.shopify.com/s/files/1/0431/5889/6802/files/58625991266.pdf
    • https://cdn.shopify.com/s/files/1/0428/8688/9639/files/47562659832.pdf
    • https://cdn.shopify.com/s/files/1/0430/4506/0762/files/64032503163.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/13534048661.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000067ed.bin
ac37e8ba1d54c0f62323425ae359b28f00e9da0b00900268267a42273766c904
pdf-font-stream PDF embedded font (sfnt) at offset 0x67ED 4980 bytes
font_01_sfnt_off00007904.bin
41b452cc242f084dcff6ea70fa16a3facb1404b3f6eafbc2e4178bc4515257c5
pdf-font-stream PDF embedded font (sfnt) at offset 0x7904 10792 bytes
font_02_sfnt_off00009ddc.bin
8a483a387f3528d14a2f00f09054886c589ec6b564ec5b76e5e1b3cb137045ac
pdf-font-stream PDF embedded font (sfnt) at offset 0x9DDC 16064 bytes