Malicious PDF — malware analysis report

Static analysis result for SHA-256 543de537a4b86d16…

MALICIOUS

PDF

49.9 KB Created: 2020-08-08 03:33:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b5f7f3b8ce9d554bf27991fd254cc454 SHA-1: 8ddbc8ae00ac83c1a2c26f9fafbb2b736165a50b SHA-256: 543de537a4b86d1659540f151762a29a9ad584026667deb9d8bc8009911936f7
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains multiple embedded links, with a critical heuristic identifying a link to a known malicious redirector at 'https://ttraff.cc/pify?keyword=classroom+language+book+pdf'. Another heuristic indicates a large number of external PDF links, suggesting a link farm for SEO manipulation or traffic redirection. The ML classifier strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains references to 'classroom language book pdf' and the malicious URL, reinforcing the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=classroom+language+book+pdf
    • http://files.wynedesygns.com/uploads/1/3/1/8/131857791/gowepuxusexu-dapunade-nojoxiwuriba-sanazi.pdf
    • http://files.navajosam.com/uploads/1/3/1/0/131070918/jekuruvitef.pdf
    • http://files.donslettersfromthenorth.com/uploads/1/3/2/6/132695551/0d2caeaa742109.pdf
    • https://cdn.shopify.com/s/files/1/0434/4777/9478/files/xujiwazawivugiwabu.pdf
    • https://cdn.shopify.com/s/files/1/0431/6305/8340/files/biology_notes_zambia.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/23631451812.pdf
    • https://cdn.shopify.com/s/files/1/0427/6020/8540/files/6198620850.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/dejozetopugewafapo.pdf
    • https://cdn.shopify.com/s/files/1/0432/1758/4285/files/gojonejenejadimebulafasi.pdf
    • https://cdn.shopify.com/s/files/1/0430/5915/1009/files/35813331250.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/65233410578.pdf
    • https://cdn.shopify.com/s/files/1/0428/2220/5607/files/pixigesobo.pdf
    • https://cdn.shopify.com/s/files/1/0434/6282/0005/files/wezejaxegufepu.pdf
    • https://cdn.shopify.com/s/files/1/0431/5417/8216/files/veloxuzafi.pdf
    • https://cdn.shopify.com/s/files/1/0427/4647/8759/files/mefizidezopanomujew.pdf
    • https://cdn.shopify.com/s/files/1/0434/0806/4677/files/vukagolisuware.pdf
    • https://cdn.shopify.com/s/files/1/0437/2211/3192/files/88748662484.pdf
    • https://cdn.shopify.com/s/files/1/0428/5153/2963/files/58356444662.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000083fd.bin
15e2bc8337d70f0cd7a92e2e0e422890f52c401529d7963c74bdbfde7db60a99
pdf-font-stream PDF embedded font (sfnt) at offset 0x83FD 5472 bytes
font_01_sfnt_off00009678.bin
70864ebd5c132943bcce43595e7c87ca7759cfe0b9fff91f9302bf87a353f808
pdf-font-stream PDF embedded font (sfnt) at offset 0x9678 10468 bytes