Malicious PDF — malware analysis report

Static analysis result for SHA-256 f24541a80b8db8fe…

MALICIOUS

PDF

66.7 KB Created: 2020-08-22 19:42:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 978e35e3121e24872a4e989e4a8266e6 SHA-1: 734a10088ac95e2bc2ccb162067f4fc56724bacd SHA-256: f24541a80b8db8fe27429b219274754993f8ece811188dd2c14e680573e1e2c3
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=balance+sheet+translation+to+arabic'. This URL is likely used to redirect the user to a malicious site. The document also contains a PDF link farm heuristic, indicating a large number of external links, many hosted on Shopify. The ML classifier strongly flagged this PDF as malicious. The document body, though heavily corrupted, contains the text 'Balance sheet translation to arabic' and the malicious URL, reinforcing the phishing pretext.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=balance+sheet+translation+to+arabic
    • http://files.faerychildcare.ca/uploads/1/3/0/9/130969037/mutizoberojudebuwoz.pdf
    • http://files.yogaskies.net/uploads/1/3/2/7/132740182/nizidukoroloju.pdf
    • http://files.mmzurita.com/uploads/1/3/1/3/131380894/nezazozo.pdf
    • https://cdn.shopify.com/s/files/1/0431/9153/3725/files/sibujewekewafute.pdf
    • https://cdn.shopify.com/s/files/1/0428/7424/1187/files/18674654653.pdf
    • https://cdn.shopify.com/s/files/1/0431/3025/7568/files/81072901867.pdf
    • https://cdn.shopify.com/s/files/1/0435/8724/0093/files/apportion_crossword_answer.pdf
    • https://cdn.shopify.com/s/files/1/0434/3247/6838/files/woxigabo.pdf
    • https://cdn.shopify.com/s/files/1/0433/7487/0689/files/principles_of_biochemistry_lehninger_download.pdf
    • https://cdn.shopify.com/s/files/1/0431/2308/1378/files/bigavugovomevowofa.pdf
    • https://cdn.shopify.com/s/files/1/0437/3712/0933/files/zumalulozugetitebepasulo.pdf
    • https://cdn.shopify.com/s/files/1/0429/7526/4919/files/libros_apocrifos_macabeos.pdf
    • https://cdn.shopify.com/s/files/1/0429/6366/5055/files/gaguwopel.pdf
    • https://cdn.shopify.com/s/files/1/0431/0004/5469/files/74704086697.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off0000c629.bin
10e29ecb0a41b907221df897c71f15a82c1296a7e58182f83c8e2014c21d7196
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xC629 31644 bytes
font_00_sfnt_off0000924c.bin
2d818f3e0c6f15d1551d50a5af81005a53478a7bb0f8eb309f065518ce27a420
pdf-font-stream PDF embedded font (sfnt) at offset 0x924C 5076 bytes
font_01_sfnt_off0000a377.bin
33657597eecc6f4155047d2d4f583de3e626c18cf8f5051df8350e562051acac
pdf-font-stream PDF embedded font (sfnt) at offset 0xA377 10148 bytes