Malicious PDF — malware analysis report

Static analysis result for SHA-256 9fbdc1c821165ba3…

MALICIOUS

PDF

72.7 KB Created: 2020-08-06 13:14:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a4a851fdf672d81067ee927825cfc6ce SHA-1: f14eb05ac55e3ef32fffd21e3e05a8accadff205 SHA-256: 9fbdc1c821165ba3de84359fa67b379091cc9e47ad0e963dbbfe20f07dff504d
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, many of which point to a redirector service (ttraff.com) that is known to host malicious content. The document body, though heavily obfuscated, contains the URL that is also present in the heuristics. This suggests the PDF is designed to trick users into visiting a malicious site under the guise of providing Amharic mezmur lyrics.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=amharic+mezmur+lyrics+pdf
    • http://files.mrsjankowski.com/uploads/1/3/1/0/131070866/rejujuk-kelorawulepov.pdf
    • http://files.elsahenderson.net/uploads/1/3/1/3/131384656/remexirajete_rugexaxuxifub_vababinonubeki.pdf
    • http://files.milltownmonitor.com/uploads/1/3/1/0/131070588/2452102.pdf
    • http://files.coopersmastiffs.com/uploads/1/3/1/6/131636748/duwovekobesati.pdf
    • http://files.cefmiwaynecounty.com/uploads/1/3/1/3/131398085/2f13162ea22c03.pdf
    • https://cdn.shopify.com/s/files/1/0432/6434/4219/files/95000903091.pdf
    • https://cdn.shopify.com/s/files/1/0432/0192/1184/files/xodekavabodupo.pdf
    • https://cdn.shopify.com/s/files/1/0435/0597/5462/files/salupiwekekir.pdf
    • https://cdn.shopify.com/s/files/1/0429/7188/9817/files/nexaxomox.pdf
    • https://cdn.shopify.com/s/files/1/0439/4971/9720/files/clep_spanish_language_examination_guide.pdf
    • https://cdn.shopify.com/s/files/1/0430/0816/3993/files/jilefosudewedaladatol.pdf
    • https://cdn.shopify.com/s/files/1/0431/3831/8487/files/message_in_a_bottle_tab.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/muzoguganava.pdf
    • https://cdn.shopify.com/s/files/1/0437/1926/2363/files/tau_paint_schemes.pdf
    • https://cdn.shopify.com/s/files/1/0432/2649/7182/files/xipuwiruwadifajopig.pdf
    • https://cdn.shopify.com/s/files/1/0433/6674/4214/files/safufasunejobusig.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004f19.bin
e3318293e136fe7733d54622564d8c91156350990f2d36bdcffd1cf2ed4d2885
pdf-font-stream PDF embedded font (sfnt) at offset 0x4F19 40168 bytes
font_01_sfnt_off0000b940.bin
a2caebe246362ad2ea31a5db156fa9b1873dc1ffa191771cf52a9a9c212c6d37
pdf-font-stream PDF embedded font (sfnt) at offset 0xB940 5124 bytes
font_02_sfnt_off0000caa5.bin
f0c3526477985180e7206394dc7ebd72e472f21b014d4a64fabb2950f38a5105
pdf-font-stream PDF embedded font (sfnt) at offset 0xCAA5 10320 bytes
font_03_sfnt_off0000ebfe.bin
d788bb0209c1d08bf5b0a60eac12785080213e2743e6762896f8074b97f13a6f
pdf-font-stream PDF embedded font (sfnt) at offset 0xEBFE 7860 bytes
font_04_sfnt_off000106e7.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0x106E7 4324 bytes