Malicious PDF — malware analysis report

Static analysis result for SHA-256 c0e17ad4f012023d…

MALICIOUS

PDF

150.1 KB Created: 2020-08-06 17:18:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 04e03080c88865f1a9d85ee53f416003 SHA-1: 1b7856da2792299f7e0f2c6172ed1026bc83370c SHA-256: c0e17ad4f012023df4b6054a2c3a5dd119c36735f31413cb2ea6444c245bfde8
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing indicating a malicious redirector link. The primary malicious URL identified is https://ttraff.ru/pify?keyword=d.+o.+c+maroc+pdf. This suggests the document's purpose is to lure the user to this external site, which is likely hosting malicious content or phishing pages. No scripts were extracted, but the presence of the malicious URL and the ML classifier's high confidence score strongly indicate a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=d.+o.+c+maroc+pdf
    • http://berivisu.sail-cg.com/uploads/1/3/0/9/130969060/diwiwozozani-luxekikoporu-titurimos-guvenud.pdf
    • http://files.charlenedixontaxservice.com/uploads/1/3/1/3/131380083/8491459.pdf
    • http://files.blindwolfstudios.com/uploads/1/3/0/9/130969158/karasupagub-wasededizanafa-dafuvobipi.pdf
    • http://files.katrinarecoveryquilts.org/uploads/1/3/1/6/131636947/8954810.pdf
    • https://cdn.shopify.com/s/files/1/0432/8787/1646/files/podulusipepu.pdf
    • https://cdn.shopify.com/s/files/1/0430/7386/3842/files/16862253751.pdf
    • https://cdn.shopify.com/s/files/1/0427/9622/0572/files/nedegu.pdf
    • https://cdn.shopify.com/s/files/1/0428/7312/7079/files/ugly_electrical_book.pdf
    • https://cdn.shopify.com/s/files/1/0431/9703/8756/files/tijutojovibatepovofom.pdf
    • https://cdn.shopify.com/s/files/1/0430/4365/1735/files/woxaxavowexatisivi.pdf
    • https://cdn.shopify.com/s/files/1/0431/8904/3358/files/tosilosonemazukezebapipet.pdf
    • https://cdn.shopify.com/s/files/1/0435/1344/6564/files/79167161964.pdf
    • https://cdn.shopify.com/s/files/1/0427/9749/8535/files/40616332341.pdf
    • https://cdn.shopify.com/s/files/1/0436/5395/5742/files/xaxulu.pdf
    • https://cdn.shopify.com/s/files/1/0431/6263/2360/files/fundamental_of_differential_equations_9th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0432/2308/9307/files/fimew.pdf
    • https://cdn.shopify.com/s/files/1/0434/2166/3397/files/3457274712.pdf
    • https://cdn.shopify.com/s/files/1/0435/1826/3464/files/74824792277.pdf
    • https://cdn.shopify.com/s/files/1/0437/4845/8647/files/future_value_in_excel.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_007_off0002133d.bin
d06d91992a034293223c377e2a8cdb462ce2644256cc0981b29de7b831ac5d25
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2133D 21948 bytes
font_00_sfnt_off0001cf72.bin
5d14a0d04def6f90c52287e8cc7a424118416bc698cc2bd6dfd5e2a613ae4e40
pdf-font-stream PDF embedded font (sfnt) at offset 0x1CF72 4560 bytes
font_01_sfnt_off0001dee3.bin
8bd645e604c72e57c416f9529321261b9b7350d38d0884f97ceea8047d984b51
pdf-font-stream PDF embedded font (sfnt) at offset 0x1DEE3 16636 bytes
font_03_sfnt_off00023a30.bin
a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f
pdf-font-stream PDF embedded font (sfnt) at offset 0x23A30 4324 bytes