Malicious PDF — malware analysis report

Static analysis result for SHA-256 cfcb855f57962b5a…

MALICIOUS

PDF

57.8 KB Created: 2020-08-10 02:43:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b29157aa8b0b355512c0f27f8841b02e SHA-1: 36218dad8389607322e1d75d7a3e90bba0ffa34b SHA-256: cfcb855f57962b5a6f36f8933950e185aa8ffa9e9b136eea02c8365b89ac898f
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.ru/pify?keyword=bulleh+shah+poetry+pdf'. This indicates the document's primary purpose is to redirect users to malicious sites. The presence of a large number of external PDF links, many pointing to potentially compromised Shopify domains, further supports the SEO link farm tactic. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=bulleh+shah+poetry+pdf
    • http://niwew.sehlstudios.com/uploads/1/3/1/0/131069839/vuxexusixivolafilin.pdf
    • http://files.allstudentsallstandards.org/uploads/1/3/0/9/130969489/9451411.pdf
    • http://files.iesagency.com/uploads/1/3/1/3/131384169/187825.pdf
    • https://cdn.shopify.com/s/files/1/0435/2484/9815/files/addendum_to_rental_agreement.pdf
    • https://cdn.shopify.com/s/files/1/0454/5187/0358/files/internal_capsule_anatomy.pdf
    • https://cdn.shopify.com/s/files/1/0430/1216/1685/files/small_estate_affidavit_florida.pdf
    • https://cdn.shopify.com/s/files/1/0433/4636/2523/files/putujajoge.pdf
    • https://cdn.shopify.com/s/files/1/0435/7272/3875/files/dowofenivumumodosasikoso.pdf
    • https://cdn.shopify.com/s/files/1/0440/8963/9077/files/sowepefofazegipovog.pdf
    • https://cdn.shopify.com/s/files/1/0431/7433/0517/files/5332971717.pdf
    • https://cdn.shopify.com/s/files/1/0431/2875/0241/files/5771972327.pdf
    • https://cdn.shopify.com/s/files/1/0440/3278/6597/files/acoso_psicologico_laboral.pdf
    • https://cdn.shopify.com/s/files/1/0432/7555/0876/files/87782069867.pdf
    • https://cdn.shopify.com/s/files/1/0436/7689/3334/files/latex_in_jupyter_notebook.pdf
    • https://cdn.shopify.com/s/files/1/0431/5840/5275/files/14464369611.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off0000b151.bin
fd94e979576868d4bac7a0557333823e3d2efbcd8145055c55ecea294b01f23e
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xB151 17744 bytes
font_00_sfnt_off00006e59.bin
db9bc8ed31d161889739328ec806f229fdc1b6c08097d2e5fc48cb454087e932
pdf-font-stream PDF embedded font (sfnt) at offset 0x6E59 5008 bytes
font_01_sfnt_off00007f83.bin
619fcbff6d9f09d4168bd5c82e2a43b59447d902eacdebf751096691971db0b1
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F83 3908 bytes
font_02_sfnt_off00008ec3.bin
00392fe48533add7d94f02f3ad8bd412bc3a394cde6fa935d5d8a0e68dda454d
pdf-font-stream PDF embedded font (sfnt) at offset 0x8EC3 10120 bytes
font_04_sfnt_off0000cb97.bin
1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361
pdf-font-stream PDF embedded font (sfnt) at offset 0xCB97 4324 bytes