Malicious PDF — malware analysis report

Static analysis result for SHA-256 9939a9e944e6cd8c…

MALICIOUS

PDF

172.1 KB Created: 2020-08-01 07:10:40 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9ab8aa08ebc0945a89701e5c9cc59692 SHA-1: 3ba4416a8b3eefa8e876317cc436a35eb531644c SHA-256: 9939a9e944e6cd8c71699cb4823c0419862750a1b403318cffcae11385060486
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.002 Spearphishing Attachment

The PDF contains a critical heuristic firing indicating a malicious redirector link to 'https://ttraff.cc/pify?keyword=708+296+4502'. The ML classifier also strongly flagged this PDF as malicious. The document body, though heavily obfuscated, appears to contain the same malicious URL, suggesting the primary intent is to lure the user to this external resource.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=708+296+4502
    • http://files.societehistoriquenipissingouest.com/uploads/1/3/1/8/131856200/5392923.pdf
    • http://files.appletonepiscopal.org/uploads/1/3/0/8/130813777/5247092.pdf
    • http://files.bigfootontario.com/uploads/1/3/0/7/130739524/pesabuvoken.pdf
    • https://cdn.shopify.com/s/files/1/0434/5711/8374/files/2859709368.pdf
    • https://cdn.shopify.com/s/files/1/0431/4248/0021/files/xedotab.pdf
    • https://cdn.shopify.com/s/files/1/0432/5638/1597/files/bilowurajotojovurajonutim.pdf
    • https://cdn.shopify.com/s/files/1/0431/0358/4409/files/77858719599.pdf
    • https://cdn.shopify.com/s/files/1/0437/5855/1189/files/55732981427.pdf
    • https://cdn.shopify.com/s/files/1/0430/7045/5965/files/dusus.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/14490041284.pdf
    • https://cdn.shopify.com/s/files/1/0434/0085/5706/files/pefiduroxizopibun.pdf
    • https://cdn.shopify.com/s/files/1/0432/8669/1998/files/bedutonexebod.pdf
    • https://cdn.shopify.com/s/files/1/0432/8059/7152/files/341756479.pdf
    • https://cdn.shopify.com/s/files/1/0433/1136/6309/files/xusoxamivukok.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00025f91.bin
2df24decc980f0456a7c68defa83e94cd60ffb16417789aa63d29d8a82b3d655
pdf-font-stream PDF embedded font (sfnt) at offset 0x25F91 5136 bytes
font_01_sfnt_off0002712e.bin
c33a47731601a5e54409b8d7c6d2b2c17f412c429bf1a9f3e9be16dec7037775
pdf-font-stream PDF embedded font (sfnt) at offset 0x2712E 16292 bytes