Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d2b0f4bfbfcb1ab…

MALICIOUS

PDF

52.1 KB Created: 2020-08-17 16:59:41 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0286aee55e7715cd34ed1e3499e42777 SHA-1: 432ec4b9c1953fa295d1e2b0788d30849e5c4577 SHA-256: 9d2b0f4bfbfcb1abc6ba3a5fe121b4190007c1610be9f8caca628e1ca70e6933
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a high number of embedded links, many pointing to external resources, which is characteristic of a link farm. One of the primary links, 'https://ttraff.com/pify?keyword=docker+swarm+azure+template', is identified as a malicious redirector. The document body, though heavily obfuscated, contains this URL, suggesting the document's purpose is to redirect the user to malicious infrastructure. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=docker+swarm+azure+template
    • http://files.tammyandtommytravel.com/uploads/1/3/1/6/131606396/busejanofenikom-xodadejilugu-pibidanufos.pdf
    • http://files.infolibrarian.net/uploads/1/3/2/6/132695525/dosixejusefute_titotazoliludel.pdf
    • http://nulagoj.roc2change.com/uploads/1/3/2/6/132682905/zulabal-vilig-divebuwa-pujinejovozifa.pdf
    • http://files.mangareader.com/uploads/1/3/1/4/131406947/sipetitabesonetu.pdf
    • http://files.rejectrobotics.com/uploads/1/3/1/4/131412858/69fb380c026.pdf
    • https://cdn.shopify.com/s/files/1/0450/1697/3476/files/19234103408.pdf
    • https://cdn.shopify.com/s/files/1/0428/1715/9335/files/4725672380.pdf
    • https://cdn.shopify.com/s/files/1/0428/7945/1289/files/2571190945.pdf
    • https://cdn.shopify.com/s/files/1/0428/2246/7740/files/48834967016.pdf
    • https://cdn.shopify.com/s/files/1/0428/7738/6911/files/83193351110.pdf
    • https://cdn.shopify.com/s/files/1/0432/2505/5389/files/wenugafepipisufav.pdf
    • https://cdn.shopify.com/s/files/1/0440/6630/8246/files/adverb_of_frequency.pdf
    • https://cdn.shopify.com/s/files/1/0431/2019/7781/files/mewela.pdf
    • https://cdn.shopify.com/s/files/1/0439/4467/3448/files/ajax_php_contact_form_with_validation.pdf
    • https://cdn.shopify.com/s/files/1/0431/3595/9191/files/45359684479.pdf
    • https://cdn.shopify.com/s/files/1/0434/2287/5797/files/wuvavalewogewipipuzi.pdf
    • https://cdn.shopify.com/s/files/1/0431/3559/8758/files/41434063373.pdf
    • https://cdn.shopify.com/s/files/1/0433/7270/7990/files/xejogisorinejimetogo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off0000813f.bin
72af8e5a439aa09d64fac33482de026160413a7c00fdb80283179ea5158594fd
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x813F 6700 bytes
font_00_sfnt_off00006f4b.bin
ca1f8709eb180373d48f6d22bbc6b0246d6936fa04b074ab677448fe53a0e4ad
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F4B 5284 bytes
font_02_sfnt_off0000930c.bin
d4d909a6c725e4c0011bb25c8e6324a07f5c57816d8a5a314afacd85c5df6c84
pdf-font-stream PDF embedded font (sfnt) at offset 0x930C 15320 bytes