Malicious PDF — malware analysis report

Static analysis result for SHA-256 95f541d6eaacd012…

MALICIOUS

PDF

43.2 KB Created: 2020-08-16 18:55:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 230f09da3e90b7f94d7036b139e99760 SHA-1: 30e5f2e7461adbc344fd97fdc8529e9c82e1256a SHA-256: 95f541d6eaacd012fb12c82219980af6780ab5dd72e924fa8baa2fa8baa02fc0
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged as malicious by a machine learning classifier and contains a critical heuristic indicating a link to known malicious redirector infrastructure. The document body, though heavily obfuscated, contains the URL that triggers the malicious redirector. The presence of numerous external PDF links, many hosted on cdn.shopify.com, suggests a link farm or SEO poisoning attempt to disguise the malicious intent. The primary malicious URL identified is https://ttraff.ru/pify?keyword=aircraft+accident+reports+faa, which likely leads to a phishing or malware distribution site.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=aircraft+accident+reports+faa
    • http://files.whatsthewordinc.com/uploads/1/3/1/6/131607010/290351.pdf
    • https://cdn.shopify.com/s/files/1/0435/8812/4835/files/89694333920.pdf
    • https://cdn.shopify.com/s/files/1/0430/8297/3345/files/the_boondocks_season_3_torrent.pdf
    • https://cdn.shopify.com/s/files/1/0438/0796/5345/files/characteristics_of_scientific_management_theory.pdf
    • https://cdn.shopify.com/s/files/1/0427/6443/5612/files/vinen.pdf
    • https://cdn.shopify.com/s/files/1/0430/9857/0909/files/70875940182.pdf
    • https://cdn.shopify.com/s/files/1/0431/1266/1152/files/tiridevi.pdf
    • https://cdn.shopify.com/s/files/1/0432/0215/0557/files/crab_leg_cracker.pdf
    • https://cdn.shopify.com/s/files/1/0431/5476/8021/files/19317033507.pdf
    • https://cdn.shopify.com/s/files/1/0434/8831/3506/files/multivariable_calculus_james_stewart_8th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0428/7882/8700/files/gopro_hero_4_updates.pdf
    • https://cdn.shopify.com/s/files/1/0437/4288/8097/files/adenauer_novaes.pdf
    • https://cdn.shopify.com/s/files/1/0429/1257/9747/files/30203960710.pdf
    • https://cdn.shopify.com/s/files/1/0432/0441/1556/files/xibaganukuvajojipi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006b67.bin
1fe37bb7f0a11889208a9ea56b4d0fbca1267ccba0296b78e2ff6892d8a81f0e
pdf-font-stream PDF embedded font (sfnt) at offset 0x6B67 5104 bytes
font_01_sfnt_off00007cbf.bin
887c14a55f17de3a37dc87dab1deb3d5ca42be33eaf42cb60c4aa150fc43e1f5
pdf-font-stream PDF embedded font (sfnt) at offset 0x7CBF 10280 bytes