Malicious PDF — malware analysis report

Static analysis result for SHA-256 8601355f6e99ba23…

MALICIOUS

PDF

60.0 KB Created: 2020-08-12 01:57:12 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 066ebedc564d62c8836375a1cbb1c254 SHA-1: 24b727f5332e5aefa7b80747b70da95b9e8240e6 SHA-256: 8601355f6e99ba2336b156b5d462f8ec1fce6288d25817aacb99db8a7db22772
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.ru/pify?keyword=adverbial+clause+of+result+pdf'. This indicates the document's primary purpose is to redirect users to malicious infrastructure. Additionally, a PDF link farm heuristic was triggered, suggesting an attempt to manipulate search engine results or distribute multiple malicious links. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=adverbial+clause+of+result+pdf
    • http://files.sanantoniodivers.com/uploads/1/3/0/7/130776592/wexigusenara-zufedet.pdf
    • http://files.svitakwood.com/uploads/1/3/1/4/131407890/eecba7.pdf
    • http://files.nicolesmithenergy.com/uploads/1/3/0/7/130739239/melurumonoramawusefa.pdf
    • https://cdn.shopify.com/s/files/1/0429/2050/9596/files/7354442832.pdf
    • https://cdn.shopify.com/s/files/1/0428/8135/1839/files/hybrid_renewable_energy_systems.pdf
    • https://cdn.shopify.com/s/files/1/0428/0333/1231/files/digital_multimeter_dt9205a_manual.pdf
    • https://cdn.shopify.com/s/files/1/0431/1734/6965/files/89537596973.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/dadimutixiwukigojubiw.pdf
    • https://cdn.shopify.com/s/files/1/0432/2790/6206/files/pugidedupifenofudepu.pdf
    • https://cdn.shopify.com/s/files/1/0438/5013/7760/files/financial_accounting_weil_14th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0434/7691/0242/files/13914348185.pdf
    • https://cdn.shopify.com/s/files/1/0435/6302/4542/files/csv_to_json_python.pdf
    • https://cdn.shopify.com/s/files/1/0432/8026/9462/files/gaxutevuva.pdf
    • https://cdn.shopify.com/s/files/1/0437/1175/8504/files/56016782681.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a398.bin
b7f317aa0f29cd34df008dc84d8f376d2685882a57a4a5cd0d86477d0adf885a
pdf-font-stream PDF embedded font (sfnt) at offset 0xA398 2828 bytes
font_01_sfnt_off0000ad93.bin
fcb8ca2dda4dad95f6cf02283aebea5aa67fa1327a097bd85a248e2452e456f2
pdf-font-stream PDF embedded font (sfnt) at offset 0xAD93 5340 bytes
font_02_sfnt_off0000bfc7.bin
6feed64c398862fed4bcbc904782918faf19a8c11af2f3378b388265805b8bbf
pdf-font-stream PDF embedded font (sfnt) at offset 0xBFC7 10464 bytes