Malicious PDF — malware analysis report

Static analysis result for SHA-256 ee7923346be4d34a…

MALICIOUS

PDF

149.3 KB Created: 2020-08-11 18:55:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9c97f052d1715a4e70447f518cf5e4ea SHA-1: ee786692bf4f4147da96d54fe183eb8764c43690 SHA-256: ee7923346be4d34a6c7ad9d268a13dddbfac8c61e6cd38ac5fc09cf36f27b0ba
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing indicating a malicious redirector link. The embedded URL, 'https://ttraff.cc/pify?keyword=geotechnical+engineering+laboratory+manual+pdf', is directly linked to malicious infrastructure. The document body, though heavily obfuscated, also contains this URL, reinforcing the phishing pretext. The ML classifier also flagged this PDF with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=geotechnical+engineering+laboratory+manual+pdf
    • http://files.thesonsetmefree.com/uploads/1/3/2/6/132696174/wasejodudulog_dixowobati_fejorerokogow_nibon.pdf
    • http://files.jessicaharperyoga.com/uploads/1/3/2/6/132695828/tewekulu-kukane.pdf
    • http://rojipakuf.triplethreatns.com/uploads/1/3/0/7/130738614/1767825.pdf
    • http://nazox.therefugelapeer.org/uploads/1/3/1/3/131380600/xodabedo_rowimikuze_zijomurenixejex.pdf
    • https://cdn.shopify.com/s/files/1/0430/5059/8562/files/jimonibut.pdf
    • https://cdn.shopify.com/s/files/1/0437/7778/6018/files/cisco_ccna_lab_manual.pdf
    • https://cdn.shopify.com/s/files/1/0432/3491/8558/files/form_4_mathematics_notes.pdf
    • https://cdn.shopify.com/s/files/1/0434/0878/5562/files/18494809358.pdf
    • https://cdn.shopify.com/s/files/1/0430/9227/9445/files/56853038353.pdf
    • https://cdn.shopify.com/s/files/1/0431/5276/9192/files/16086567002.pdf
    • https://cdn.shopify.com/s/files/1/0434/1281/6034/files/revosivege.pdf
    • https://cdn.shopify.com/s/files/1/0432/4442/1282/files/pisipesegodujed.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/96626323422.pdf
    • https://cdn.shopify.com/s/files/1/0431/1361/1421/files/sepisetulopetuzepu.pdf
    • https://cdn.shopify.com/s/files/1/0430/9070/6589/files/188044460.pdf
    • https://cdn.shopify.com/s/files/1/0430/7356/8919/files/felonan.pdf
    • https://cdn.shopify.com/s/files/1/0430/4103/0293/files/fewugomusixupajuputa.pdf
    • https://cdn.shopify.com/s/files/1/0437/9534/9661/files/sevilla_albeniz_piano.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001a960.bin
1c106c103fc6ae3144487e6ebc0bd3fd7d0881128e89c1092f7a4e2409b25050
pdf-font-stream PDF embedded font (sfnt) at offset 0x1A960 8488 bytes
font_01_sfnt_off0001c002.bin
01206dc1becbd2be18ae818ea11c50a3f4f59bbaa9a9747fdc50e82fb98ba13f
pdf-font-stream PDF embedded font (sfnt) at offset 0x1C002 8272 bytes
font_02_sfnt_off0001da48.bin
573f8cc8923e691ef5a62d6d369de575f02831d39c79f9201f2d1e75c7660743
pdf-font-stream PDF embedded font (sfnt) at offset 0x1DA48 5664 bytes
font_03_sfnt_off0001ed72.bin
e6ef1070fe110e09fdf6bef938d0dd901ba4047105bbf626610727e05d38d2aa
pdf-font-stream PDF embedded font (sfnt) at offset 0x1ED72 8976 bytes
font_04_sfnt_off0001ff33.bin
c567e299ca22cc881bef072a01b4a68ec89ecead2cdc14f54e48924ab652f04f
pdf-font-stream PDF embedded font (sfnt) at offset 0x1FF33 16088 bytes
font_05_sfnt_off00023139.bin
116e1aefc1bdc9fdbdc8bc4ca32ed8fc2a9096b6ae60b76e258fcc2d5524df3d
pdf-font-stream PDF embedded font (sfnt) at offset 0x23139 16112 bytes