Malicious PDF — malware analysis report

Static analysis result for SHA-256 9dafe871eed6d4fd…

MALICIOUS

PDF

64.0 KB Created: 2020-08-28 10:26:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b2594da719cc503516c0030db8cd5ee9 SHA-1: d2586ba37b6039ad8b5eff6b55e3ec3e8ea6ba59 SHA-256: 9dafe871eed6d4fd348df97b3bcbf0ed24d324df15abf56e118b2091155fafff
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link farm and a critical redirector link to 'https://ttraff.cc/pify?keyword=castlevania+circle+of+the+moon+map', indicating a lure to malicious infrastructure. The ML classifier also strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains the same redirector URL, reinforcing the malicious intent. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=castlevania+circle+of+the+moon+map
    • http://files.melvinmorsemd.com/uploads/1/3/1/4/131453399/634181.pdf
    • http://files.destockmarket.org/uploads/1/3/2/7/132712235/gajubonutu_guget_xifogufab.pdf
    • https://cdn.shopify.com/s/files/1/0429/6704/0154/files/canon_powershot_sx500_is_manual.pdf
    • https://cdn.shopify.com/s/files/1/0440/7050/2550/files/46460767645.pdf
    • https://cdn.shopify.com/s/files/1/0428/4094/8903/files/jumugakorofa.pdf
    • https://cdn.shopify.com/s/files/1/0428/9508/1635/files/rijirobafarewi.pdf
    • https://cdn.shopify.com/s/files/1/0437/6880/7586/files/form_i-_134_instructions.pdf
    • https://cdn.shopify.com/s/files/1/0429/0979/4463/files/damevet.pdf
    • https://cdn.shopify.com/s/files/1/0430/6065/8333/files/famefajozoteri.pdf
    • https://cdn.shopify.com/s/files/1/0432/2174/5823/files/vitamin_sources_and_functions_worksheet.pdf
    • https://cdn.shopify.com/s/files/1/0429/9443/4202/files/ancient_greek_costume.pdf
    • https://cdn.shopify.com/s/files/1/0434/2654/5820/files/rocket_propulsion_elements_8th_edition_solutions_manual.pdf
    • https://cdn.shopify.com/s/files/1/0450/8113/3219/files/lovozubudiniwifonipo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008549.bin
823e47eaa9fb4688747da3cbc7f0d16ee306f51e714c737e650ae25a91523c76
pdf-font-stream PDF embedded font (sfnt) at offset 0x8549 17220 bytes
font_01_sfnt_off0000bcbd.bin
565549955f7d9e09e2f235802fceebc31f37461e1faac79d790cbd8ad85f342c
pdf-font-stream PDF embedded font (sfnt) at offset 0xBCBD 5220 bytes
font_02_sfnt_off0000ce56.bin
c56088939b17e308234a6b344f0ebf5d9cdd73c5d54f342daf23cc65941674d1
pdf-font-stream PDF embedded font (sfnt) at offset 0xCE56 10696 bytes