Malicious PDF — malware analysis report

Static analysis result for SHA-256 e921e28e680769b3…

MALICIOUS

PDF

45.8 KB Created: 2020-08-15 02:07:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 120c4832f1f7b7ef170cf55c407ddfe5 SHA-1: 8601f1e1f2770f7f0bb5b079d356c5c14b8b5aed SHA-256: e921e28e680769b362d58da812bde860f4c2b7f535dc11ee7d8dc2dcce328263
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a significant number of embedded links, with a critical heuristic firing for a malicious redirector and another for a PDF link farm. The primary malicious URL identified is https://ttraff.cc/pify?keyword=elmo+sugar+meme+template, which likely serves as a gateway to further malicious content. The document body is heavily obfuscated and contains remnants of the redirector URL, suggesting it's part of the lure mechanism. The presence of numerous Shopify links, many of which are confirmed benign, alongside the malicious redirector, indicates a sophisticated attempt at SEO manipulation or content distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=elmo+sugar+meme+template
    • http://files.chrisenrightfinewoodworking.com/uploads/1/3/1/6/131606963/cf80fcc7a6fa2.pdf
    • http://files.tenwebtv.com/uploads/1/3/1/0/131069899/6ec828f1ca7121.pdf
    • http://files.missouriattorney.com/uploads/1/3/2/6/132682882/lufaduzudumosi.pdf
    • http://files.mplsimpulse.org/uploads/1/3/0/7/130776218/6509067.pdf
    • http://files.jeremylewistuba.com/uploads/1/3/1/6/131606490/wupuzag.pdf
    • https://cdn.shopify.com/s/files/1/0432/6375/4404/files/wepemaxo.pdf
    • https://cdn.shopify.com/s/files/1/0431/5981/4306/files/nujefarovuderas.pdf
    • https://cdn.shopify.com/s/files/1/0433/7709/8910/files/52281950166.pdf
    • https://cdn.shopify.com/s/files/1/0434/1317/6469/files/brushless_excitation_system.pdf
    • https://cdn.shopify.com/s/files/1/0433/1280/8091/files/boss_gt1_manual_espaol.pdf
    • https://cdn.shopify.com/s/files/1/0433/7899/9446/files/davulifobomevekegafuk.pdf
    • https://cdn.shopify.com/s/files/1/0440/6021/3398/files/mixamubopif.pdf
    • https://cdn.shopify.com/s/files/1/0428/5582/5567/files/python_module_manually.pdf
    • https://cdn.shopify.com/s/files/1/0432/1335/7211/files/tawaripu.pdf
    • https://cdn.shopify.com/s/files/1/0433/3538/5247/files/possessive_adjective_exercises_with_answers.pdf
    • https://cdn.shopify.com/s/files/1/0429/7831/2355/files/cours_anglais_amricain.pdf
    • https://cdn.shopify.com/s/files/1/0437/3879/2085/files/60859024409.pdf
    • https://cdn.shopify.com/s/files/1/0446/4774/3651/files/winter_dreams_summary.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com/s/files/1/0446/4774/3651/files/winter_dreams_s

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000688d.bin
b0eb2bf2561a5545dd0eb77a2dc1fd85bb1f50aa340081b7ee57da542bb611ab
pdf-font-stream PDF embedded font (sfnt) at offset 0x688D 4824 bytes
font_01_sfnt_off000078fd.bin
10ef9b6c2659b7b332fc20331ae2965d1fa94b0ce5001c5d40cfc4082cbe3b91
pdf-font-stream PDF embedded font (sfnt) at offset 0x78FD 10372 bytes
font_02_sfnt_off00009c24.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0x9C24 4324 bytes