Malicious PDF — malware analysis report

Static analysis result for SHA-256 e9a806e5d320b894…

MALICIOUS

PDF

42.0 KB Created: 2020-08-23 18:07:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: af4a77215a39db5cc5efe5aa9cacb5d0 SHA-1: 85eff0519622fd470abab5c3198b7f5dcf311d8e SHA-256: e9a806e5d320b894deb3ec174bbf19a30a4b7cf8793a6f8d1ef7a1c3c29729d1
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a mass external link farm, with a critical heuristic firing for a malicious redirector link to 'https://ttraff.com/pify?keyword=integer+number+line+worksheets+grade+6'. The document body, though heavily obfuscated, also contains this URL, suggesting the primary intent is to redirect users to malicious infrastructure. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=integer+number+line+worksheets+grade+6
    • http://files.sleepingwithavampire.com/uploads/1/3/2/7/132740545/5312940.pdf
    • http://files.wsfishfarm.com/uploads/1/3/1/3/131398406/57b709129.pdf
    • https://cdn.shopify.com/s/files/1/0427/9477/8791/files/26985537934.pdf
    • https://cdn.shopify.com/s/files/1/0435/4048/0155/files/non_canonical_books_of_the_bible.pdf
    • https://cdn.shopify.com/s/files/1/0434/7707/4077/files/fahrenheit_451_part_1_summary.pdf
    • https://cdn.shopify.com/s/files/1/0431/8488/1824/files/rivugonomebepasut.pdf
    • https://cdn.shopify.com/s/files/1/0437/1175/8491/files/free_english_lessons.pdf
    • https://cdn.shopify.com/s/files/1/0434/4279/8757/files/10172944516.pdf
    • https://cdn.shopify.com/s/files/1/0434/5892/0610/files/best_rpg_games_for_android_online.pdf
    • https://cdn.shopify.com/s/files/1/0434/7330/5750/files/sisulifapupo.pdf
    • https://cdn.shopify.com/s/files/1/0429/4157/9420/files/31097754568.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006596.bin
61219fb568fe3199d9def4d6ede2e8f0a7ee315269c1d99c98188711f6c64709
pdf-font-stream PDF embedded font (sfnt) at offset 0x6596 5628 bytes
font_01_sfnt_off00007891.bin
627d1f1fe88de1ce1f23902a498846b3c28d0084f42bea854ce4c2967b51a2e8
pdf-font-stream PDF embedded font (sfnt) at offset 0x7891 10252 bytes