Malicious PDF — malware analysis report

Static analysis result for SHA-256 9c6183a1cb286e1f…

MALICIOUS

PDF

66.0 KB Created: 2020-08-10 13:20:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fab203a9be4895fa0e5360b998168950 SHA-1: ee6e79b4137e9fe8ffeff0d3f7783c034538e270 SHA-256: 9c6183a1cb286e1fcb2e57c10c8d92ddc7886a12eb9c653422daa51b1620cd32
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a critical heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.cc/pify?keyword=irrationality+stuart+sutherland+pdf'. This indicates the document's primary purpose is to redirect users to malicious infrastructure. The presence of a large number of external PDF links also suggests a link farm or SEO poisoning attempt. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=irrationality+stuart+sutherland+pdf
    • http://files.vanitieslove.com/uploads/1/3/0/7/130738762/1916089.pdf
    • http://files.akademosresearch.com/uploads/1/3/2/7/132712508/7548713.pdf
    • http://files.theboondocs.org/uploads/1/3/1/6/131606760/luben-gaxupikivire.pdf
    • http://files.mojohomeautomation.com/uploads/1/3/0/7/130739974/3d41d0928e.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/37144816260.pdf
    • https://cdn.shopify.com/s/files/1/0433/7870/4536/files/7986008423.pdf
    • https://cdn.shopify.com/s/files/1/0431/4392/1820/files/einstein_photoelectric_effect.pdf
    • https://cdn.shopify.com/s/files/1/0434/7399/3890/files/sed_cheat_sheet.pdf
    • https://cdn.shopify.com/s/files/1/0440/5533/0966/files/46519079428.pdf
    • https://cdn.shopify.com/s/files/1/0430/9476/9821/files/24214179781.pdf
    • https://cdn.shopify.com/s/files/1/0430/2451/5229/files/61005075964.pdf
    • https://cdn.shopify.com/s/files/1/0436/6431/0425/files/39127271761.pdf
    • https://cdn.shopify.com/s/files/1/0433/5396/4712/files/4563846303.pdf
    • https://cdn.shopify.com/s/files/1/0437/7808/0919/files/samibutodibitumuja.pdf
    • https://cdn.shopify.com/s/files/1/0428/6611/4727/files/21132219529.pdf
    • https://cdn.shopify.com/s/files/1/0430/4823/9257/files/zinanunepixeramatuk.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c55f.bin
ddb3c5f79dd21872dc622b7310f479b723fe979e08b2d62cd7611107d8ff24da
pdf-font-stream PDF embedded font (sfnt) at offset 0xC55F 5168 bytes
font_01_sfnt_off0000d6ee.bin
d0a54e0631db4a217e9215c0ae40d02fb251a35614693751fcf954daaa8e5aa0
pdf-font-stream PDF embedded font (sfnt) at offset 0xD6EE 10564 bytes