Malicious PDF — malware analysis report

Static analysis result for SHA-256 a41e83567b24da2b…

MALICIOUS

PDF

76.7 KB Created: 2020-08-09 03:52:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c4137358ed2c67dadfbd1b371e8b2d67 SHA-1: 6ca7068e4961faff5b588efa8cb70dc0d31b4912 SHA-256: a41e83567b24da2beae5c86808412af2bc9b4cbbbb3b3ecb6fa57fb9d858adc3
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://ttraff.ru/pify?keyword=amphotericin+b+mechanism+of+action+pdf'. Additionally, it exhibits characteristics of a PDF link farm, with numerous links to external PDFs, many hosted on Shopify. The ML classifier strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains the same malicious URL. The primary attack vector appears to be luring the user to a malicious site via the embedded link.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=amphotericin+b+mechanism+of+action+pdf
    • http://tatala.leisuretravelsrilanka.com/uploads/1/3/1/6/131606289/7ac4c52b.pdf
    • http://files.baycountrycrabbingsupply.com/uploads/1/3/1/4/131437085/bb5f6fd740ef65b.pdf
    • http://files.ceclayton.com/uploads/1/3/2/6/132681409/453d018ab6.pdf
    • http://files.barrons-conferences.com/uploads/1/3/1/4/131409170/3066792.pdf
    • https://cdn.shopify.com/s/files/1/0432/7351/9269/files/ketogenic_diet_meal_plan.pdf
    • https://cdn.shopify.com/s/files/1/0430/7006/2754/files/9512221512.pdf
    • https://cdn.shopify.com/s/files/1/0430/5007/4269/files/xebefatokebedobabufive.pdf
    • https://cdn.shopify.com/s/files/1/0429/1241/5907/files/jenopax.pdf
    • https://cdn.shopify.com/s/files/1/0429/4914/8838/files/dibag.pdf
    • https://cdn.shopify.com/s/files/1/0434/2287/5797/files/anger_management.pdf
    • https://cdn.shopify.com/s/files/1/0427/7328/2983/files/medowukave.pdf
    • https://cdn.shopify.com/s/files/1/0430/8582/4154/files/1963956367.pdf
    • https://cdn.shopify.com/s/files/1/0437/8253/7365/files/nfs_most_wanted_bmw.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/jedufejaselikaruratemop.pdf
    • https://cdn.shopify.com/s/files/1/0431/0630/4166/files/31519590562.pdf
    • https://cdn.shopify.com/s/files/1/0431/5460/4198/files/bosako.pdf
    • https://cdn.shopify.com/s/files/1/0435/2396/5080/files/thailand_australia_free_trade_agreement.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c7c1.bin
2143bf87e157b0d270cf6eb18b8341abf37857762388538ecbb1d3336c8a93ad
pdf-font-stream PDF embedded font (sfnt) at offset 0xC7C1 5492 bytes
font_01_sfnt_off0000da3a.bin
ccc51736ebddbf098ee486f26ef5ce8837d902f2e6ad15a50fadd0738be723d8
pdf-font-stream PDF embedded font (sfnt) at offset 0xDA3A 17368 bytes
font_02_sfnt_off00011013.bin
f80b9f84d6ea16074f67da7a904ab41e14e5a44612b81a97f195d72f9bd2a496
pdf-font-stream PDF embedded font (sfnt) at offset 0x11013 16160 bytes