Malicious PDF — malware analysis report

Static analysis result for SHA-256 84a24025f20df7e9…

MALICIOUS

PDF

37.9 KB Created: 2020-08-10 13:48:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f4f27682a16b5e53bdd6edc8eb9a1398 SHA-1: dfd8c3a93f87b599ec1c2289629d33de50ab92ba SHA-256: 84a24025f20df7e98468164ed13f763975d12e80b72d5c0dc623b694820d77de
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.ru/pify?keyword=bible+timeline+pdf+download'. This URL is presented within the document body, suggesting a social engineering lure to trick users into clicking it. The presence of numerous other PDF links, many hosted on Shopify, indicates a link farm strategy, likely to improve search engine ranking for the malicious content or to obscure the ultimate destination. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=bible+timeline+pdf+download
    • http://files.corefitathletics.com/uploads/1/3/1/0/131070291/pibapiwel_mimofavakipux.pdf
    • http://files.oconnart.com/uploads/1/3/2/6/132681976/a1d0372b689f.pdf
    • http://files.breezeeweezee.com/uploads/1/3/1/6/131637307/bikejetadaf.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/5578033559.pdf
    • https://cdn.shopify.com/s/files/1/0438/3778/4224/files/roxio_easy_vhs_to_dvd_3_plus.pdf
    • https://cdn.shopify.com/s/files/1/0437/7804/8162/files/ars_poetica_horace_summary.pdf
    • https://cdn.shopify.com/s/files/1/0431/4241/4492/files/jaduwoj.pdf
    • https://cdn.shopify.com/s/files/1/0439/4418/1928/files/67064094863.pdf
    • https://cdn.shopify.com/s/files/1/0428/0041/4883/files/50424817188.pdf
    • https://cdn.shopify.com/s/files/1/0429/6795/7658/files/wexasasilukijol.pdf
    • https://cdn.shopify.com/s/files/1/0433/7503/4520/files/jorojowazuzime.pdf
    • https://cdn.shopify.com/s/files/1/0434/6901/3157/files/xamoretegap.pdf
    • https://cdn.shopify.com/s/files/1/0433/9869/3022/files/7112467531.pdf
    • https://cdn.shopify.com/s/files/1/0431/2429/3796/files/wewivasekabiko.pdf
    • https://cdn.shopify.com/s/files/1/0429/1778/9862/files/english_lesson_plan.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000056a9.bin
81d81bb32e36a72b65975ecccd810f6572750aaf5b9bdf087a95bd74f39a9217
pdf-font-stream PDF embedded font (sfnt) at offset 0x56A9 5196 bytes
font_01_sfnt_off00006846.bin
0195f3e214b5adfd2315110160f70f454e4de420b1a0b63724b35056d5ba3abb
pdf-font-stream PDF embedded font (sfnt) at offset 0x6846 10080 bytes