Malicious PDF — malware analysis report

Static analysis result for SHA-256 e2e437292644200c…

MALICIOUS

PDF

48.4 KB Created: 2020-08-11 04:08:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ee5bb7a0080ea2a35c82dc014d7fa70a SHA-1: b74ad2b59c89959d30279fd5fb6d8855713e9773 SHA-256: e2e437292644200c5c64b4e10a7de1ec9beff61b5a4e649a5cf4435269c7614d
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains numerous embedded links, with a critical heuristic firing indicating a link to a known malicious redirector infrastructure. The document body also contains the URL 'https://ttraff.cc/pify?keyword=captopril+davis+pdf', which is likely intended to lead the user to malicious content. The presence of multiple Shopify URLs suggests an attempt to disguise the malicious links among seemingly benign ones. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=captopril+davis+pdf
    • http://wazivomo.tinlizziesokc.com/uploads/1/3/1/4/131454106/bdd98d13368.pdf
    • http://files.sequoiagemandmineralsociety.org/uploads/1/3/1/4/131438316/jejopilazilateb.pdf
    • http://files.sterlingruralfire.com/uploads/1/3/1/0/131070476/zunidiferidomi.pdf
    • https://cdn.shopify.com/s/files/1/0428/0313/4627/files/nevawuvudusojatiwexagefep.pdf
    • https://cdn.shopify.com/s/files/1/0439/3366/3400/files/anchorage_food_handlers_card.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/lagikemirulufuwetore.pdf
    • https://cdn.shopify.com/s/files/1/0432/5851/1510/files/91183768873.pdf
    • https://cdn.shopify.com/s/files/1/0432/6119/8500/files/vuravaxasosumexubi.pdf
    • https://cdn.shopify.com/s/files/1/0430/6350/9143/files/mezoxabo.pdf
    • https://cdn.shopify.com/s/files/1/0436/2646/3392/files/59756446831.pdf
    • https://cdn.shopify.com/s/files/1/0438/6196/7013/files/30332292884.pdf
    • https://cdn.shopify.com/s/files/1/0431/6043/6887/files/54388293814.pdf
    • https://cdn.shopify.com/s/files/1/0427/7148/0742/files/58848008998.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007353.bin
84ade49c691966152bd67f6fbb122dab6e537e7eb216f25b994e7d9537474df7
pdf-font-stream PDF embedded font (sfnt) at offset 0x7353 4684 bytes
font_01_sfnt_off00008350.bin
aa81434ec6abccb1f1c66a4528016ed4dd796eb18bc6d466e3bc2562bcb09429
pdf-font-stream PDF embedded font (sfnt) at offset 0x8350 10464 bytes
font_02_sfnt_off0000a721.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0xA721 4324 bytes