Malicious PDF — malware analysis report

Static analysis result for SHA-256 c031b9755054d103…

MALICIOUS

PDF

63.3 KB Created: 2020-09-15 03:05:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0381a79b30e65e7d94df72bf3a769fc5 SHA-1: 4f96e4dc41cd82dded7dab4a772c395c9f6d7b5d SHA-256: c031b9755054d103bab33696912ae0169bc7b37fb46f55589e48078a3bd8fe5b
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=us+army+alice+pack+manual+pdf'. This URL is presented within the document body, disguised as a link to a US Army Alice Pack manual, indicating a social engineering lure. The presence of numerous external PDF links further suggests an attempt to distribute malicious content or engage in SEO manipulation for malicious purposes. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=us+army+alice+pack+manual+pdf
    • https://cdn.shopify.com/s/files/1/0434/3808/0166/files/65681977040.pdf
    • https://cdn.shopify.com/s/files/1/0440/2066/2422/files/jikoravibunepolulugilav.pdf
    • https://cdn.shopify.com/s/files/1/0436/3878/4158/files/92061358671.pdf
    • https://cdn.shopify.com/s/files/1/0432/1227/5870/files/using_social_media_in_the_workplace_to_communicate.pdf
    • https://cdn.shopify.com/s/files/1/0429/0415/8375/files/14443332804.pdf
    • https://cdn.shopify.com/s/files/1/0434/2022/1607/files/translation_rotation_reflection_worksheet.pdf
    • https://cdn.shopify.com/s/files/1/0438/7025/7320/files/57504913644.pdf
    • https://static.usrfiles.com/ugd/bf57b5_2f1856a8612f40d0ae0e24402c63ab7d.pdf
    • https://static.usrfiles.com/ugd/78c764_8bcc2a1316ca49289355188294752f8d.pdf
    • https://static.usrfiles.com/ugd/dfb5f8_68b3adf77bb646378e5f6f9292a699ac.pdf
    • https://static.usrfiles.com/ugd/934fc3_2c864e2657ef4107b98e2d535fbb1b09.pdf
    • https://static.usrfiles.com/ugd/5360f8_ed2e7cd5d29c42edba4a27dd18d8d71b.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000b343.bin
1bd40fd244ada223508c8e86bde3c0925cc2ef9edccc3723f5ed58f7efac4f2d
pdf-font-stream PDF embedded font (sfnt) at offset 0xB343 5456 bytes
font_01_sfnt_off0000c5ce.bin
669e1dedc6615fa5a0d33c3208833261cc7b7023bf042946207637d1c3a2f25e
pdf-font-stream PDF embedded font (sfnt) at offset 0xC5CE 13296 bytes