Malicious PDF — malware analysis report

Static analysis result for SHA-256 7be87c2e00eed962…

MALICIOUS

PDF

45.1 KB Created: 2020-08-10 16:12:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 05d683139da565da00830a2f3b99f9e8 SHA-1: b51b8c6bf93bb8fb2c22d239bfc96c0e1104893a SHA-256: 7be87c2e00eed9628c355ec908f3229ff93e5f89ebd4eb6be17da505c215f7e4
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.ru/pify?keyword=german+vocabulary+lists+by+topic+pdf'. The document body, though heavily obfuscated, also contains this URL, suggesting the document's primary purpose is to lure users to this malicious site. The ML classifier also strongly flagged this PDF as malicious. The presence of numerous external PDF links further supports the SEO link farm heuristic.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=german+vocabulary+lists+by+topic+pdf
    • http://files.konsultservices.com/uploads/1/3/1/8/131872087/nulanudifo.pdf
    • http://files.brewsandmews.com/uploads/1/3/0/8/130874109/de25d.pdf
    • http://files.mydrycleaningguy.com/uploads/1/3/1/4/131407849/a5cc9aa05354f60.pdf
    • http://files.pnba-artists.org/uploads/1/3/1/0/131070711/db357bcc0b38b39.pdf
    • http://files.kortarsmuveszet.com/uploads/1/3/1/8/131856664/vimaretanizig.pdf
    • https://cdn.shopify.com/s/files/1/0429/3191/2857/files/20418714117.pdf
    • https://cdn.shopify.com/s/files/1/0430/6403/3429/files/89001941840.pdf
    • https://cdn.shopify.com/s/files/1/0430/8110/5562/files/marulifibaziwijosa.pdf
    • https://cdn.shopify.com/s/files/1/0434/6111/6064/files/akuntansi_perbankan_taswan_edisi_3.pdf
    • https://cdn.shopify.com/s/files/1/0434/1350/4156/files/sugomulefimekezozoziwi.pdf
    • https://cdn.shopify.com/s/files/1/0434/8795/3053/files/full_block_business_letter_format.pdf
    • https://cdn.shopify.com/s/files/1/0434/8834/6262/files/62799263811.pdf
    • https://cdn.shopify.com/s/files/1/0430/2562/9335/files/49652799267.pdf
    • https://cdn.shopify.com/s/files/1/0430/5498/9466/files/how_to_set_homepage_on_chrome.pdf
    • https://cdn.shopify.com/s/files/1/0434/6845/6088/files/bsc_1st_year_chemistry_syllabus_2020.pdf
    • https://cdn.shopify.com/s/files/1/0433/7886/8387/files/cetosis_bovina_fisiopatologia.pdf
    • https://cdn.shopify.com/s/files/1/0431/5637/3670/files/answer_sheet_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0431/2216/3876/files/jafipaduburazonixut.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007175.bin
a85c5d94f217d8acc3d6962b8392a489586916943b8b9fc2dd6d7211044c5385
pdf-font-stream PDF embedded font (sfnt) at offset 0x7175 5636 bytes
font_01_sfnt_off00008497.bin
2c7556aba9b1282925ee5f511c819e97716e6aeb1a3f96b7e585b3e7f02dc9e5
pdf-font-stream PDF embedded font (sfnt) at offset 0x8497 10224 bytes