Malicious PDF — malware analysis report

Static analysis result for SHA-256 7fd1e8338b955435…

MALICIOUS

PDF

50.8 KB Created: 2020-08-17 08:40:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 97c0c5f63fd8e51a76eca9f26e0bdf7e SHA-1: 15f2f0cb097844db8c66dc717d76a3b6a9724679 SHA-256: 7fd1e8338b955435f3924d93e2efe4e6b961129437ae09efbfce28e48992eefa
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF file contains a large number of embedded links, many pointing to Shopify domains, which is indicative of a link farm designed to manipulate search engine results or distribute content. One critical heuristic firing identified a link to a known malicious redirector at `https://ttraff.ru/pify?keyword=special+forces+group+2+apk+only`. The ML classifier also strongly flagged this PDF as malicious. The presence of numerous links suggests an attempt to lure users to malicious sites, likely for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=special+forces+group+2+apk+only
    • http://xozizatas.nathonkelley.com/uploads/1/3/0/7/130740013/mazunu-bebevini.pdf
    • http://files.sagardenclub.org/uploads/1/3/2/8/132814071/5e226f2e6.pdf
    • http://files.saneegypt.com/uploads/1/3/2/7/132740612/0b1cdf386f.pdf
    • http://files.bradentonfamilywellness.com/uploads/1/3/1/0/131070918/defiwaligotuxo.pdf
    • http://files.karaikudivoyage.us/uploads/1/3/2/3/132302999/tigebanijuw.pdf
    • https://cdn.shopify.com/s/files/1/0429/7211/9193/files/2426524242.pdf
    • https://cdn.shopify.com/s/files/1/0429/8804/4442/files/soxakejigizafaxemevexoz.pdf
    • https://cdn.shopify.com/s/files/1/0431/8609/4248/files/nalogul.pdf
    • https://cdn.shopify.com/s/files/1/0432/0781/9422/files/40942528440.pdf
    • https://cdn.shopify.com/s/files/1/0431/3504/1693/files/anemia_aplasica_elsevier.pdf
    • https://cdn.shopify.com/s/files/1/0437/7369/0017/files/81925683254.pdf
    • https://cdn.shopify.com/s/files/1/0436/9462/0837/files/9235601961.pdf
    • https://cdn.shopify.com/s/files/1/0436/2731/5353/files/activate_windows_7_64_bit.pdf
    • https://cdn.shopify.com/s/files/1/0435/4693/5451/files/4949220492.pdf
    • https://cdn.shopify.com/s/files/1/0432/7797/5717/files/86939379316.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006412.bin
e4f0b37823e2521fd5d1d871bd0d80f869135a6bba2793eb42342f487bb8b026
pdf-font-stream PDF embedded font (sfnt) at offset 0x6412 3456 bytes
font_01_sfnt_off00007071.bin
3245b40dc5e71c0a73e58f29f3f8f41217342dff19bb00c6cfaf87e08c8fd7ef
pdf-font-stream PDF embedded font (sfnt) at offset 0x7071 5384 bytes
font_02_sfnt_off000082cd.bin
ee0d20151ca4872f0fe8ed325ea1b7732f0ca75ee4fbdabbae6f901c7c1d2727
pdf-font-stream PDF embedded font (sfnt) at offset 0x82CD 14472 bytes
font_03_sfnt_off0000afa6.bin
9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2
pdf-font-stream PDF embedded font (sfnt) at offset 0xAFA6 4324 bytes