Malicious PDF — malware analysis report

Static analysis result for SHA-256 89a8a5cd041186b7…

MALICIOUS

PDF

88.8 KB Created: 2020-08-10 03:23:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a1f38b85801d97700c337ea0d426895f SHA-1: 7951e3759b949aa888b0d50554a2b614d9b357ec SHA-256: 89a8a5cd041186b799df5adc46c1cc691ab074741f3ae6cef29d131abc451050
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains numerous embedded links, with one critical heuristic identifying a link to known malicious redirector infrastructure. The document body, though heavily obfuscated, contains a URL that appears to be the same as the one flagged by the heuristic. This suggests the PDF's primary purpose is to redirect users to malicious content, likely for phishing or malware delivery. The presence of multiple Shopify links, while individually benign, contributes to a link farm pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=benjamin+graham+intelligent+investor+free+pdf
    • http://files.stmarklutheranroseville.org/uploads/1/3/1/6/131606668/netiluxesitez-lowulixufepunu-lopekiwit-dibupagu.pdf
    • http://files.fortunatierra.com/uploads/1/3/0/7/130776673/6966068.pdf
    • http://files.westtechmobile.ca/uploads/1/3/1/6/131637562/rapigew.pdf
    • http://lufow.kidacademy.org/uploads/1/3/2/8/132814930/9108716.pdf
    • http://dorutuves.drlindseynd.com/uploads/1/3/1/3/131398140/0589d0a4d.pdf
    • https://cdn.shopify.com/s/files/1/0435/2756/9576/files/61664143787.pdf
    • https://cdn.shopify.com/s/files/1/0433/6805/4940/files/42753189816.pdf
    • https://cdn.shopify.com/s/files/1/0430/3680/3233/files/92030461359.pdf
    • https://cdn.shopify.com/s/files/1/0428/7463/4403/files/29625659701.pdf
    • https://cdn.shopify.com/s/files/1/0429/7061/1861/files/92920182245.pdf
    • https://cdn.shopify.com/s/files/1/0431/7977/0019/files/goposurizuxisotolidamuw.pdf
    • https://cdn.shopify.com/s/files/1/0431/0512/4516/files/noxotegunapawubigu.pdf
    • https://cdn.shopify.com/s/files/1/0435/9376/0931/files/hp_w2207h_manual.pdf
    • https://cdn.shopify.com/s/files/1/0438/0711/3373/files/revista_eudora_ciclo_6.pdf
    • https://cdn.shopify.com/s/files/1/0431/7849/2072/files/mujuboremonusatoniko.pdf
    • https://cdn.shopify.com/s/files/1/0430/1737/1797/files/nidaw.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010677.bin
2e6f14cea7e6dab31a234c2ab9336eb986daafc05a51a97dd03b5d7cbb9f4182
pdf-font-stream PDF embedded font (sfnt) at offset 0x10677 5640 bytes
font_01_sfnt_off0001198e.bin
81b452a241e31684d43619e92ab0d24ccd11aa0a1cbd058e564467c63c9bfa86
pdf-font-stream PDF embedded font (sfnt) at offset 0x1198E 11168 bytes
font_02_sfnt_off00013fea.bin
dcc4c0abc0890442b0fa2aa32d0d4460407ba6a80c6f9f092138d4912a9fa5ed
pdf-font-stream PDF embedded font (sfnt) at offset 0x13FEA 16184 bytes