Malicious PDF — malware analysis report

Static analysis result for SHA-256 54e2ba4264c7fe84…

MALICIOUS

PDF

71.3 KB Created: 2020-07-31 10:50:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b4da8316cb0263ede485cb0a6807079c SHA-1: 13992497c0e04a8720ba0d882f272e3e3513fef6 SHA-256: 54e2ba4264c7fe8422ce83dd30cdedcd0b2e6d0f718065fa0386f35cb1f5550a
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a malicious redirector link disguised as a download for 'Amharic bible study pdf download'. The document also exhibits characteristics of a link farm, with numerous external PDF links, many hosted on cdn.shopify.com. The primary malicious URL identified is ttraff.ru, which is known for redirecting to malicious content. The ML classifier strongly indicates maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=amharic+bible+study+pdf+download
    • http://files.performingartsworkshops.org/uploads/1/3/1/3/131384777/zejapepuzufozodipa.pdf
    • http://files.mcpatgrace.org/uploads/1/3/1/3/131398036/liburesuguw.pdf
    • http://files.masasailing.org/uploads/1/3/0/8/130873921/904ca.pdf
    • https://cdn.shopify.com/s/files/1/0432/7312/6052/files/vapixeposageduxu.pdf
    • https://cdn.shopify.com/s/files/1/0429/1903/5033/files/larazidapuzopatepetu.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/dedepisolutiri.pdf
    • https://cdn.shopify.com/s/files/1/0440/8731/2536/files/49101297695.pdf
    • https://cdn.shopify.com/s/files/1/0431/0482/9602/files/tusazo.pdf
    • https://cdn.shopify.com/s/files/1/0433/5638/9528/files/95117307668.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/pejuzesuloroxutebed.pdf
    • https://cdn.shopify.com/s/files/1/0432/2571/0750/files/xulizodotilosoj.pdf
    • https://cdn.shopify.com/s/files/1/0432/0549/2904/files/16684646294.pdf
    • https://cdn.shopify.com/s/files/1/0432/0726/2367/files/72688475790.pdf
    • https://cdn.shopify.com/s/files/1/0430/4073/5381/files/41011449010.pdf
    • https://cdn.shopify.com/s/files/1/0428/1538/9855/files/lawinilatez.pdf
    • https://cdn.shopify.com/s/files/1/0435/1036/6362/files/954360366.pdf
    • https://cdn.shopify.com/s/files/1/0437/5802/6903/files/19837654922.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/98572357872.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007f7c.bin
e5d68c5aa81270ef57c17e6ab58819befdbc9750867011e4d2c37a21101e3847
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F7C 26084 bytes
font_01_sfnt_off0000c463.bin
b9921f6f7d6fb5186a401677766c1bef624d5b5c3c3568dbe73c2271ab0a1488
pdf-font-stream PDF embedded font (sfnt) at offset 0xC463 5600 bytes
font_02_sfnt_off0000d74f.bin
b553dd8935eab2e411f5e51600d147a4cad298318997893c145a2ad1e4bf7402
pdf-font-stream PDF embedded font (sfnt) at offset 0xD74F 9916 bytes
font_03_sfnt_off0000f98f.bin
0646a63a478fe53468b8dbbe05b608d617a04836cde27f490c8d0ce00ae8a9f2
pdf-font-stream PDF embedded font (sfnt) at offset 0xF98F 16164 bytes