Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef36f3ab9a1febd6…

MALICIOUS

PDF

44.3 KB Created: 2020-08-28 15:09:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b197a2f969ea75552cb07c8b10719930 SHA-1: 0f8c257178eb35618c63f9f4103db513cbc8e497 SHA-256: ef36f3ab9a1febd617640820e790bd1e15e12729d5cc5d38beaa63d252d080e6
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, many of which point to Shopify domains, but one critical link redirects to the known malicious domain 'ttraff.ru'. The document body, though heavily obfuscated, contains text that appears to be a lure related to song lyrics, likely intended to mask the malicious redirection. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=enga+karuppasamy+songs+lyrics+in+tam
    • http://files.dance4him.org/uploads/1/3/1/6/131606550/jodijodukepo.pdf
    • https://cdn.shopify.com/s/files/1/0429/2050/9596/files/mugen_1._0_download.pdf
    • https://cdn.shopify.com/s/files/1/0427/4572/5094/files/critters_a_new_binge_parents_guide.pdf
    • https://cdn.shopify.com/s/files/1/0431/1774/0199/files/cahier_de_vacances_ce2_vers_cm1.pdf
    • https://cdn.shopify.com/s/files/1/0433/4416/7064/files/23754974648.pdf
    • https://cdn.shopify.com/s/files/1/0428/9812/9059/files/96391372389.pdf
    • https://cdn.shopify.com/s/files/1/0444/3871/6583/files/vaxezazelodimamak.pdf
    • https://cdn.shopify.com/s/files/1/0430/8362/8708/files/guia_genero_dramatico.pdf
    • https://cdn.shopify.com/s/files/1/0434/1714/1415/files/machine_language_assembly_language_and_high_level_language.pdf
    • https://cdn.shopify.com/s/files/1/0428/5225/3863/files/kogesafaduzolojumatewakut.pdf
    • https://cdn.shopify.com/s/files/1/0438/7281/3211/files/functions_gcse_maths.pdf
    • https://cdn.shopify.com/s/files/1/0427/4972/2790/files/35491119468.pdf
    • https://cdn.shopify.com/s/files/1/0444/0332/7142/files/java_dice_game.pdf
    • https://cdn.shopify.com/s/files/1/0437/1995/0485/files/list_of_fatty_acids.pdf
    • https://cdn.shopify.com/s/files/1/0431/4192/2982/files/43774769338.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00006114.bin
3729d91192faaf7cd707d183dfc6ec46c1bb071627dbf949271bb5696d4a8150
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6114 10940 bytes
font_00_sfnt_off00004ed6.bin
8da3a2739ba852f8a4fac263f0b11acc81c84a591d12286194a6bc97de55cf8d
pdf-font-stream PDF embedded font (sfnt) at offset 0x4ED6 5376 bytes
font_02_sfnt_off00007c7b.bin
50064292f7678245d619c1bc10d1812808402272713a87b2b0a06a9de4ec4989
pdf-font-stream PDF embedded font (sfnt) at offset 0x7C7B 12596 bytes