Malicious PDF — malware analysis report

Static analysis result for SHA-256 9fcb0a184bb5cb63…

MALICIOUS

PDF

47.2 KB Created: 2020-08-22 17:38:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f2d020ea1b636ddb3f5f61edeef7bffe SHA-1: c37d8a06b6feb9fbfb21f2d80eb3846eef9f9da2 SHA-256: 9fcb0a184bb5cb63700a2abbf72186b478b2ed9e1531b07fb22717715e9a295f
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a deceptive lure related to 'Whatsapp app by play store' and embeds numerous links. One critical heuristic indicates a PDF link to known malicious redirector infrastructure, specifically `https://ttraff.ru/pify?keyword=whatsapp+app++by+play+store`. This suggests the document's primary purpose is to redirect users to malicious sites, likely for phishing or malware distribution. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=whatsapp+app++by+play+store
    • http://vulub.pleis.us/uploads/1/3/1/4/131438304/guvozamuli_jupamusuzese_puwexudijarew_gozikajarox.pdf
    • http://files.merimbulaunitingchurch.com.au/uploads/1/3/1/3/131398177/pinepo-sojepojomuberib.pdf
    • https://cdn.shopify.com/s/files/1/0438/4758/1856/files/alcalosis_metabolica_pdf_2020.pdf
    • https://cdn.shopify.com/s/files/1/0433/9109/0844/files/xomopafunigupanaru.pdf
    • https://cdn.shopify.com/s/files/1/0430/2969/2577/files/vopanubexogibevezowurujop.pdf
    • https://cdn.shopify.com/s/files/1/0428/8148/2919/files/78665185449.pdf
    • https://cdn.shopify.com/s/files/1/0431/3199/4280/files/lenifenurumobo.pdf
    • https://cdn.shopify.com/s/files/1/0433/6710/4664/files/principles_of_qualitative_data_analysis.pdf
    • https://cdn.shopify.com/s/files/1/0434/6635/8934/files/autodesk_revit_architecture_student.pdf
    • https://cdn.shopify.com/s/files/1/0435/2737/2955/files/xunewalezesafanemamuren.pdf
    • https://cdn.shopify.com/s/files/1/0430/2438/4154/files/25322024455.pdf
    • https://cdn.shopify.com/s/files/1/0434/7147/0742/files/tifofutejisima.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007a8b.bin
53555128318daa110fedbe2f342ed33e66604dcb83a7fe616d65b308bd0fe494
pdf-font-stream PDF embedded font (sfnt) at offset 0x7A8B 5164 bytes
font_01_sfnt_off00008c1c.bin
4a33b15d06bf0ea903ed79ae16d20fed8e918bb481fade0d407d37248fbf35ec
pdf-font-stream PDF embedded font (sfnt) at offset 0x8C1C 10668 bytes