Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f57da896efa7554…

MALICIOUS

PDF

40.4 KB Created: 2020-08-31 01:47:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c07b5423cfeab1d53f020f3ce2cf0085 SHA-1: bfe15ebac1d8a941c6a9026fc531f49b9cf0316f SHA-256: 9f57da896efa755457d8aca605821e5de5a08b0bd78bbd99a8eba9b05ab33c30
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, which is also present in the document body. This link, 'https://ttraff.club/wix?keyword=e%25C4%259Flenceli+%25C4%25B1sl%25C4%25B1k+fon+m%25C3%25BCzi%25C4%259Fi+indir', is designed to redirect users to malicious content. The document also exhibits characteristics of a PDF link farm, with numerous external links, many pointing to Shopify domains, likely for SEO manipulation or to host further malicious content. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=e%25C4%259Flenceli+%25C4%25B1sl%25C4%25B1k+fon+m%25C3%25BCzi%25C4%259Fi+indir
    • https://cdn.shopify.com/s/files/1/0431/1977/1799/files/71800162213.pdf
    • https://cdn.shopify.com/s/files/1/0438/3745/6534/files/49386946122.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/xazome.pdf
    • https://cdn.shopify.com/s/files/1/0428/9154/2681/files/wwf_no_mercy_rom.pdf
    • https://cdn.shopify.com/s/files/1/0432/9262/3001/files/mastering_chemistry.pdf
    • https://static.usrfiles.com/ugd/b8c837_8effff432bae424d9315c3df81b13c0c.pdf
    • https://static.usrfiles.com/ugd/b8c837_87e67cb6cc884dda9b20febff742b9d9.pdf
    • https://static.usrfiles.com/ugd/b8c837_2d4f321424ae4301bfb7d00787c90909.pdf
    • https://static.usrfiles.com/ugd/37428b_f2be741743fb4927af5153443bec78ee.pdf
    • https://cdn.shopify.com/s/files/1/0438/3732/5472/files/sistema_bethesda_para_tiroides.pdf
    • https://cdn.shopify.com/s/files/1/0432/4681/3344/files/oxford_arabic_to_english_dictionary.pdf
    • https://cdn.shopify.com/s/files/1/0434/0462/4021/files/zoladegofoluzet.pdf
    • https://cdn.shopify.com/s/files/1/0431/2167/2356/files/disipekeze.pdf
    • https://static.usrfiles.com/ugd/2ac701_2936124796e3448d88149de890f29a35.pdf
    • https://static.usrfiles.com/ugd/b8c837_24aea0c63e874923a51c64b47926ef78.pdf
    • https://static.usrfiles.com/ugd/23e9be_d98b837f56814c87abbf9a0e82afbccd.pdf
    • https://static.usrfiles.com/ugd/c836c3_4ad54e98b5d1477fbb77417e10590041.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000052e3.bin
b92af1371c1ec63b9db57e253ed908b63bf9892695ae63c5850538a8cfdb4346
pdf-font-stream PDF embedded font (sfnt) at offset 0x52E3 5412 bytes
font_01_sfnt_off0000650e.bin
7ef6cb6698fea806eec66effba9ae77859a8e18c03169e66e212b1421c87ab72
pdf-font-stream PDF embedded font (sfnt) at offset 0x650E 1888 bytes
font_02_sfnt_off00006e21.bin
977ba29b9a20a36b7f2cb51c1b5c905a89e7bbe2e85bb43303958cdbd888d736
pdf-font-stream PDF embedded font (sfnt) at offset 0x6E21 11588 bytes