Malicious PDF — malware analysis report

Static analysis result for SHA-256 1be90914fd568086…

MALICIOUS

PDF

66.8 KB Created: 2020-09-07 19:43:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9bb877bcfcd95c485c5553debbb0921f SHA-1: c96440faac54cec1de58740f019d60a61424fe02 SHA-256: 1be90914fd568086e3f8d84f6276aae310b19d61474e997aba04116604397ce1
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a malicious redirector link disguised as a free antivirus download. The link, https://ttraff.me/wix?keyword=antivirus+android+gratuit+telecharger, is the primary indicator of malicious intent. The document body, though heavily obfuscated, contains text related to antivirus downloads and the redirector URL, reinforcing the lure. The PDF structure and embedded content were flagged by multiple critical heuristics, indicating a deliberate attempt to redirect users to harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=antivirus+android+gratuit+telecharger
    • https://static.usrfiles.com/ugd/902d29_e7bed9e66c664b85843b3335dc54ab7a.pdf
    • https://static.usrfiles.com/ugd/027f51_92cd7831766f4258b038a6363cfc65c4.pdf
    • https://static.usrfiles.com/ugd/b8c837_4bc6a584438644838b5e22bc81baf359.pdf
    • https://static.usrfiles.com/ugd/90423f_5ea1409b491248a99f5782055116059d.pdf
    • https://cdn.shopify.com/s/files/1/0435/9094/2888/files/44023352365.pdf
    • https://cdn.shopify.com/s/files/1/0439/9765/9294/files/english_alphabet_cursive.pdf
    • https://cdn.shopify.com/s/files/1/0432/4923/8178/files/kuvusedadamagusula.pdf
    • https://cdn.shopify.com/s/files/1/0436/3649/0398/files/sap_purchase_order_inbound_delivery_report.pdf
    • https://cdn.shopify.com/s/files/1/0438/6599/7472/files/css_font_stack.pdf
    • https://cdn.shopify.com/s/files/1/0432/7538/7043/files/pejifurobumuj.pdf
    • https://cdn.shopify.com/s/files/1/0428/9354/1535/files/anandam_movie_free_naa_songs.pdf
    • https://cdn.shopify.com/s/files/1/0434/0000/3747/files/41051265543.pdf
    • https://cdn.shopify.com/s/files/1/0430/5358/0437/files/99550348702.pdf
    • https://cdn.shopify.com/s/files/1/0428/4832/1692/files/kinunuvaloxax.pdf
    • https://cdn.shopify.com/s/files/1/0432/4560/0931/files/retarumupuriragavi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009411.bin
16f571858ccea7f65a148767b261e651977817b648c0f3cdbeb41a44489bc908
pdf-font-stream PDF embedded font (sfnt) at offset 0x9411 16488 bytes
font_01_sfnt_off0000c841.bin
e16ccdc9774c23ff70a321e38238cf77ac0a9cf0d88429533929ab0168c5d6b2
pdf-font-stream PDF embedded font (sfnt) at offset 0xC841 5248 bytes
font_02_sfnt_off0000da18.bin
393b1b33b967d1a5e7d3bc87ed109a2893e83ef0efe86748dd944652cc36394b
pdf-font-stream PDF embedded font (sfnt) at offset 0xDA18 10352 bytes