Malicious PDF — malware analysis report

Static analysis result for SHA-256 ed21d9cc8fc5c33f…

MALICIOUS

PDF

46.2 KB Created: 2020-08-06 01:22:19 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c190774a4e3f7f84c51fa757ce575689 SHA-1: 735f3308aa3e95424a1cb1bb6501aab8bbca9027 SHA-256: ed21d9cc8fc5c33f00630ef68a2f7bd44d709ef010dac4ff1a4963d6f6a2f648
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a heuristic firing for a malicious redirector link pointing to 'https://ttraff.ru/pify?keyword=cashew+nut+production+in+tanzania+pdf'. Additionally, the PDF exhibits characteristics of a link farm, embedding numerous external links, many of which point to Shopify domains. The ML classifier strongly flagged this PDF as malicious. The primary attack pattern involves luring the user to a malicious site via the embedded redirector.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=cashew+nut+production+in+tanzania+pdf
    • http://rimimifu.meowstories.us/uploads/1/3/1/4/131483281/b713b2ced.pdf
    • http://files.designsbysarahmeyer.com/uploads/1/3/1/4/131437139/d49d002b3c4b.pdf
    • http://files.olsenandcompany.com/uploads/1/3/0/7/130739833/faniwawovogaru_sibukote_tukixoroge_xijalofusukuleg.pdf
    • http://files.kaiserfarmfresh.com/uploads/1/3/0/7/130775969/4746433.pdf
    • http://files.kittsonskitchen.com/uploads/1/3/1/3/131378993/4118135.pdf
    • https://cdn.shopify.com/s/files/1/0432/4111/1716/files/35619226847.pdf
    • https://cdn.shopify.com/s/files/1/0430/4686/3005/files/15920397883.pdf
    • https://cdn.shopify.com/s/files/1/0438/1592/7965/files/zedegimaveraditilubimo.pdf
    • https://cdn.shopify.com/s/files/1/0432/4828/7912/files/great_quotes_about_life.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/9959313526.pdf
    • https://cdn.shopify.com/s/files/1/0428/2135/3635/files/nuwemofe.pdf
    • https://cdn.shopify.com/s/files/1/0436/1509/2893/files/hp_pavilion_6000_driver.pdf
    • https://cdn.shopify.com/s/files/1/0433/6317/2502/files/raw_karambwan_osrs.pdf
    • https://cdn.shopify.com/s/files/1/0428/0667/3574/files/70498807918.pdf
    • https://cdn.shopify.com/s/files/1/0437/3318/8762/files/92781934030.pdf
    • https://cdn.shopify.com/s/files/1/0432/3658/9730/files/rokirewafobepetumavila.pdf
    • https://cdn.shopify.com/s/files/1/0434/6707/9830/files/elementary_principles_of_chemical_processes.pdf
    • https://cdn.shopify.com/s/files/1/0432/8367/7339/files/66975467269.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000076c3.bin
f5743dc2d8737f0ebf65b89fd5d93647db551d8a9bccc593378cd09bc352b8c0
pdf-font-stream PDF embedded font (sfnt) at offset 0x76C3 5256 bytes
font_01_sfnt_off000088bb.bin
91f5a94b2c197452ef8002d1aeaff95ace9f7b2529d13231cc61df4a105121b7
pdf-font-stream PDF embedded font (sfnt) at offset 0x88BB 10088 bytes