Malicious PDF — malware analysis report

Static analysis result for SHA-256 cd2b9948b71c912a…

MALICIOUS

PDF

40.9 KB Created: 2020-08-18 15:13:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a48280d16e8787dc01e82837bfdc75f7 SHA-1: 67c1d8d81b1232fa6865ce2328064c7b432db940 SHA-256: cd2b9948b71c912ab9b68c85f9940b4a73c7c9b055955aebc63d93eca752ba44
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a mass link farm, with the primary link directing to a known malicious redirector at 'https://ttraff.com/pify?keyword=standard+fitted+cot+sheet+size+australia'. The document body, though heavily obfuscated, also contains this URL, suggesting the intent is to redirect the user to malicious infrastructure. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=standard+fitted+cot+sheet+size+australia
    • http://files.covingtonnazarene.com/uploads/1/3/1/3/131398097/lajelili_kofateboxasub_xunovu_kubovipig.pdf
    • http://files.reginamartyn.com/uploads/1/3/1/3/131398336/0bc461019acd976.pdf
    • http://files.rubberdirect.net/uploads/1/3/1/3/131380005/jipupo_xutajegax_zekod_verobe.pdf
    • https://cdn.shopify.com/s/files/1/0436/3422/9398/files/66568293941.pdf
    • https://cdn.shopify.com/s/files/1/0430/8772/4704/files/56228248411.pdf
    • https://cdn.shopify.com/s/files/1/0438/7710/5832/files/inequalities_worksheet_algebra_1.pdf
    • https://cdn.shopify.com/s/files/1/0432/2823/3885/files/firujorevafovenosefatulad.pdf
    • https://cdn.shopify.com/s/files/1/0429/5688/2086/files/assertive_communication_examples.pdf
    • https://cdn.shopify.com/s/files/1/0430/8549/6482/files/autocad_tutorial_in_urdu_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0432/8561/0654/files/sidezufobipodemak.pdf
    • https://cdn.shopify.com/s/files/1/0438/5931/2800/files/47131765180.pdf
    • https://cdn.shopify.com/s/files/1/0431/5539/0630/files/alfabeto_arabe.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000060c5.bin
cc4820dc7eb552d05f8f8a443fb2ddaf99b329143866fe30c823e556deb389a7
pdf-font-stream PDF embedded font (sfnt) at offset 0x60C5 5260 bytes
font_01_sfnt_off00007299.bin
ea17b87910571966277adc4b0bb79fa753b2510a4afa7ad0639b74597e5645d1
pdf-font-stream PDF embedded font (sfnt) at offset 0x7299 10704 bytes