Malicious PDF — malware analysis report

Static analysis result for SHA-256 24d4103e1941e676…

MALICIOUS

PDF

52.3 KB Created: 2020-08-04 12:24:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bd92d1b19e3f72b7138175bc17686560 SHA-1: 192017cf31d4814bba3086bfc60ca82100bbb3b4 SHA-256: 24d4103e1941e676461211503d61d7d50c419ad99b8b1cf7260821e926fd8ba9
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains numerous embedded links, many of which point to Shopify domains hosting PDF files. However, one prominent link redirects to 'ttraff.com', which is flagged as a malicious redirector. The document body, though heavily obfuscated, contains text related to 'my anti fan novel pdf' and the malicious URL, suggesting a lure to a malicious site. The presence of multiple PDF links, including a malicious redirector, indicates an attempt to drive traffic to malicious infrastructure, likely for further exploitation or phishing.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=my+anti+fan+novel+pdf
    • http://files.allisanellwood.com/uploads/1/3/0/7/130776490/vofawedapo_nalupufamepeti_lemafaxajogeno.pdf
    • http://files.timeoutsportsbarandgrill.net/uploads/1/3/1/3/131381612/zebovi.pdf
    • http://files.realsynergycommercial.com/uploads/1/3/1/4/131412558/komewesoze.pdf
    • http://files.knightsofstpeterandstpaul.com/uploads/1/3/1/0/131070204/lawemamanudobokidak.pdf
    • http://files.seafordps.org/uploads/1/3/1/8/131856163/501773.pdf
    • https://cdn.shopify.com/s/files/1/0437/0500/8293/files/nususa.pdf
    • https://cdn.shopify.com/s/files/1/0439/2127/7096/files/clean_architecture_book.pdf
    • https://cdn.shopify.com/s/files/1/0431/2412/9946/files/xepob.pdf
    • https://cdn.shopify.com/s/files/1/0432/1338/9992/files/dewex.pdf
    • https://cdn.shopify.com/s/files/1/0429/8843/7655/files/zadoxagux.pdf
    • https://cdn.shopify.com/s/files/1/0430/6763/7917/files/77447989523.pdf
    • https://cdn.shopify.com/s/files/1/0431/1239/9010/files/mopagisoziratuxaxexujep.pdf
    • https://cdn.shopify.com/s/files/1/0429/1916/6105/files/8888394920.pdf
    • https://cdn.shopify.com/s/files/1/0437/2476/7400/files/mepusavumigalebomukuniroj.pdf
    • https://cdn.shopify.com/s/files/1/0429/5812/7270/files/kupejipitalunikumuruwa.pdf
    • https://cdn.shopify.com/s/files/1/0431/8828/9694/files/71170397287.pdf
    • https://cdn.shopify.com/s/files/1/0433/3309/1480/files/79983662413.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000061b3.bin
108b90da0957a1621eca4acdd673c4192003f8e1d607ad2305c06aa85e2bda32
pdf-font-stream PDF embedded font (sfnt) at offset 0x61B3 6224 bytes
font_01_sfnt_off000076c9.bin
d7134e9500cb85af43e69030c508aa0a3914bc55d294bb8bd8c5a62f7c63c869
pdf-font-stream PDF embedded font (sfnt) at offset 0x76C9 4928 bytes
font_02_sfnt_off000087c4.bin
a9f158afb66236b58de95fd7241c87b45a3cf3d8a508fc0fad93fe75d7a582bb
pdf-font-stream PDF embedded font (sfnt) at offset 0x87C4 10764 bytes
font_03_sfnt_off0000accc.bin
abfd345a6ea1e62b83e5b81470e97c0bb38d81b9d626d8407e597eb2d2192f0c
pdf-font-stream PDF embedded font (sfnt) at offset 0xACCC 16204 bytes