Malicious PDF — malware analysis report

Static analysis result for SHA-256 bd3217fb2e400ee7…

MALICIOUS

PDF

68.1 KB Created: 2020-08-12 02:08:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b78b6fcd5acc9a0bc05bf141c9891816 SHA-1: 3929737c30efefd149805336e991b3461b5cb6cd SHA-256: bd3217fb2e400ee747eace6ac15a0fd4d134a1d1b364ac88e63d71ca90c426a0
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link to a known malicious redirector, ttraff.ru, which is likely used to obscure the final destination of the malicious payload. The document body and embedded links suggest an attempt to disguise the malicious nature by referencing a seemingly relevant topic. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=bukhari+hadith+pdf+in+bangla
    • http://files.anteupphotography.co.uk/uploads/1/3/1/4/131438059/leremojolisip.pdf
    • http://files.suzygrimshaw.net/uploads/1/3/2/8/132814239/ranorodawogepov.pdf
    • http://files.mobilemealssoaz.org/uploads/1/3/0/8/130874403/c3c3b3a79f97.pdf
    • http://files.billloellke.com/uploads/1/3/0/7/130775371/gasanomebumowef.pdf
    • https://cdn.shopify.com/s/files/1/0450/7241/6931/files/53142912678.pdf
    • https://cdn.shopify.com/s/files/1/0430/3935/9127/files/luguretunepedusunovukedur.pdf
    • https://cdn.shopify.com/s/files/1/0437/3472/8853/files/coleman_6250_generators.pdf
    • https://cdn.shopify.com/s/files/1/0431/1423/4013/files/11206712055.pdf
    • https://cdn.shopify.com/s/files/1/0435/1036/6362/files/pevelun.pdf
    • https://cdn.shopify.com/s/files/1/0446/6167/0051/files/research_paper_format_apa.pdf
    • https://cdn.shopify.com/s/files/1/0433/7002/1014/files/61355473495.pdf
    • https://cdn.shopify.com/s/files/1/0430/2969/2577/files/1157495820.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/kufanagapaxo.pdf
    • https://cdn.shopify.com/s/files/1/0434/9889/7574/files/political_allegory_in_faerie_queene.pdf
    • https://cdn.shopify.com/s/files/1/0438/2782/2749/files/30_days_english_speaking_course_book_in_tamil.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off0000e2d1.bin
69fd563ab7bcbc94034cae5480282ed12f767c50c6dbcc110f2d4f52994101d2
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xE2D1 19712 bytes
font_00_sfnt_off00007c6c.bin
59c15673f680347e415b0cd106f5e5602825026f0b3bf79d4a64791d5e81e73b
pdf-font-stream PDF embedded font (sfnt) at offset 0x7C6C 5380 bytes
font_01_sfnt_off00008ead.bin
269c356d93ebf6aa7644425bc63af9be497b8b48fab92f4fc680a1a6d62e6e37
pdf-font-stream PDF embedded font (sfnt) at offset 0x8EAD 11188 bytes
font_02_sfnt_off0000b306.bin
df3a373b06efe80c5de9dcad6900d9d2d41b3e7779873bd12be075f7e24fd625
pdf-font-stream PDF embedded font (sfnt) at offset 0xB306 15440 bytes