Malicious PDF — malware analysis report

Static analysis result for SHA-256 94508fadb92c9770…

MALICIOUS

PDF

35.6 KB Created: 2020-09-06 22:54:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 37b263caba859ea7f2280c221a19f0ee SHA-1: be5b261469df313efe11577614cb990300511df8 SHA-256: 94508fadb92c97705e7797d031054a028d8b6b826e78e290c7ac77191bdb6c58
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF contains a link farm and a direct link to a redirector, indicating a phishing or scam attempt. The embedded URL 'https://ttraff.link/pify?keyword=hey+google+today+weather+report' is flagged as malicious and likely serves as a lure. The document body, though heavily obfuscated, contains this URL and other PDF links, suggesting an attempt to drive traffic to malicious infrastructure. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/pify?keyword=hey+google+today+weather+report
    • https://cdn.shopify.com/s/files/1/0430/5184/3737/files/dopigegosafaponalalaz.pdf
    • https://cdn.shopify.com/s/files/1/0433/0346/9209/files/pneumonia_pada_anak_adalah.pdf
    • https://cdn.shopify.com/s/files/1/0434/5584/0409/files/ajcc_cancer_staging_manual_7th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0429/4367/6582/files/resize_mac_os.pdf
    • https://cdn.shopify.com/s/files/1/0431/5942/1092/files/fuwisilosolatubemafek.pdf
    • https://static.usrfiles.com/ugd/cece23_8fbf83e6ca984b5ebb3599f6edf1d926.pdf
    • https://static.usrfiles.com/ugd/4b68be_d3e27c511ddb4588bb87608d72740ae1.pdf
    • https://static.usrfiles.com/ugd/2ddd39_70d492cced674f0d8498e988387f1553.pdf
    • https://static.usrfiles.com/ugd/7598fa_3bac7b8db0b34c96809470aef1555186.pdf
    • https://static.usrfiles.com/ugd/451461_fd3bfba7a6ce444bb28a5fe7b9c0e4f1.pdf
    • https://static.usrfiles.com/ugd/787b0a_1599e250c5414778be7f2925c25fd5b9.pdf
    • https://static.usrfiles.com/ugd/6cf804_8f214cda00aa458092795d69de279b5c.pdf
    • https://static.usrfiles.com/ugd/418e76_c3dd833e812e4d0488509b8bfee97a30.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004c8d.bin
ef5d1979fecd798fc5035a0d60695380c6aafd03ba33b48edf0d77408e8d4fc5
pdf-font-stream PDF embedded font (sfnt) at offset 0x4C8D 5196 bytes
font_01_sfnt_off00005e4c.bin
1ad2fe808c1748fd22d82c08cc74405a963122a032bd8491c2ea20741ebcf749
pdf-font-stream PDF embedded font (sfnt) at offset 0x5E4C 10512 bytes