Malicious PDF — malware analysis report

Static analysis result for SHA-256 b573df0c098409f3…

MALICIOUS

PDF

40.7 KB Created: 2020-08-27 18:53:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ba2e3e2230f6bc6df6f588c3ab09eec4 SHA-1: f42795db1885f62e19de9e4f467cb96002945ec6 SHA-256: b573df0c098409f3ebc7727c2356f2e14542d933805d8968ac52b8b103aa8306
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a heuristic firing for a malicious redirector link pointing to 'https://ttraff.com/pify?keyword=eviction+notice+nc'. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded URLs, many hosted on cdn.shopify.com. The document body, though heavily obfuscated, contains the same redirector URL, reinforcing the lure. The primary attack pattern involves tricking the user into visiting a malicious URL under the guise of an eviction notice.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=eviction+notice+nc
    • http://files.sacredspace-yoga.com/uploads/1/3/1/8/131871605/1764363.pdf
    • http://files.uufunding.org/uploads/1/3/0/9/130969546/safav-kinosovekuzazod-xolevadepofono.pdf
    • https://cdn.shopify.com/s/files/1/0428/6211/7020/files/berliner_platz_4_neu_intensivtrainer.pdf
    • https://cdn.shopify.com/s/files/1/0429/3410/8323/files/90253373125.pdf
    • https://cdn.shopify.com/s/files/1/0433/4092/3048/files/xamefixavamumilejudex.pdf
    • https://cdn.shopify.com/s/files/1/0431/2560/4513/files/fuxum.pdf
    • https://cdn.shopify.com/s/files/1/0431/3333/7768/files/winesisizowuxeladaj.pdf
    • https://cdn.shopify.com/s/files/1/0434/6337/7048/files/friends_never_say_goodbay.pdf
    • https://cdn.shopify.com/s/files/1/0432/4625/6295/files/dremel_saw_max_manual.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/sabam.pdf
    • https://cdn.shopify.com/s/files/1/0437/8096/4509/files/education_during_apartheid_era.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000065ba.bin
5afad92cd4a53bb77a390010fe62b366e2b418d51c66f1c8967964f21e32933a
pdf-font-stream PDF embedded font (sfnt) at offset 0x65BA 4296 bytes
font_01_sfnt_off00007467.bin
2f1f3f0cc2d1521e6af13788b16aaae3a97bd5530eee5371c0eccae257ee0c4d
pdf-font-stream PDF embedded font (sfnt) at offset 0x7467 9940 bytes