Malicious PDF — malware analysis report

Static analysis result for SHA-256 dcfdfba96bf93b78…

MALICIOUS

PDF

58.1 KB Created: 2020-08-09 23:34:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 205e0ee59cc189f7d11c422d6de834ea SHA-1: 4ea4f888542b53aa4cc7074a18fc573a04722690 SHA-256: dcfdfba96bf93b7856aa689f56df874af02b965fd57c70fff65e7e48db48b4e3
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.ru/pify?keyword=humanistic+approach+to+learning+pdf'. Additionally, it exhibits characteristics of a PDF link farm, with numerous external links, including one to 'https://cdn.shopify.com/s/files/1/0435/6079/6318/files/zoguve.pdf'. The ML classifier strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains the same URL as the redirector link, suggesting the primary intent is to trick users into clicking this link.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=humanistic+approach+to+learning+pdf
    • http://files.myoloh.org/uploads/1/3/1/4/131437363/xiwiwokuwixu.pdf
    • http://files.barrvillemc.org/uploads/1/3/0/7/130776118/423244.pdf
    • http://files.plumislandweavingco.com/uploads/1/3/0/7/130775211/kemawem.pdf
    • https://cdn.shopify.com/s/files/1/0435/6079/6318/files/zoguve.pdf
    • https://cdn.shopify.com/s/files/1/0428/6968/6431/files/dopoworilijilukanozir.pdf
    • https://cdn.shopify.com/s/files/1/0430/6377/1293/files/how_to_make_room_heater_at_home.pdf
    • https://cdn.shopify.com/s/files/1/0434/0006/9287/files/gepave.pdf
    • https://cdn.shopify.com/s/files/1/0436/8180/8549/files/positive_and_negative_feedback_amplifier.pdf
    • https://cdn.shopify.com/s/files/1/0441/2011/3304/files/workplace_health_and_safety.pdf
    • https://cdn.shopify.com/s/files/1/0431/3251/8555/files/kosoker.pdf
    • https://cdn.shopify.com/s/files/1/0430/4424/1562/files/41630769092.pdf
    • https://cdn.shopify.com/s/files/1/0430/0954/0257/files/riduge.pdf
    • https://cdn.shopify.com/s/files/1/0430/1727/3497/files/68907369623.pdf
    • https://cdn.shopify.com/s/files/1/0431/6515/5487/files/bioactive_compounds_from_marine_organisms.pdf
    • https://cdn.shopify.com/s/files/1/0430/7025/9357/files/pabefusagakipiv.pdf
    • https://cdn.shopify.com/s/files/1/0428/8351/4527/files/jadadovotugike.pdf
    • https://cdn.shopify.com/s/files/1/0434/5479/1846/files/45621415653.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a506.bin
b755807f44dba4d8c3fe5aab16f412b05e0acbece88bab17e425ebe1c66b1a70
pdf-font-stream PDF embedded font (sfnt) at offset 0xA506 5528 bytes
font_01_sfnt_off0000b7a1.bin
d9e6393f559a93603f877c184b5a6acdc4f6550cc86f624fa191dfd645a0bcd7
pdf-font-stream PDF embedded font (sfnt) at offset 0xB7A1 10420 bytes