Malicious PDF — malware analysis report

Static analysis result for SHA-256 280ed9348b8397f4…

MALICIOUS

PDF

33.9 KB Created: 2020-09-16 22:21:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ef9719a301d9a4f46e7d7e4068a46beb SHA-1: 3a8774d957f6df7ea2fbb79c4d0805a79bcc359d SHA-256: 280ed9348b8397f4819e0658f2d8eacf250d803742ab9fb4d1bcfe36a38d5dd0
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing indicating a link to known malicious redirector infrastructure. The document body also explicitly contains the URL and a deceptive lure related to downloading an "Amazon prime video apk". This suggests the primary goal is to trick the user into visiting the malicious URL to download potentially harmful software.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=amazon+prime+video+apk+android+5.1.1
    • https://cdn.shopify.com/s/files/1/0432/5353/0788/files/96570045694.pdf
    • https://cdn.shopify.com/s/files/1/0428/0942/6079/files/xuwenime.pdf
    • https://cdn.shopify.com/s/files/1/0433/4613/3157/files/71789742301.pdf
    • https://cdn.shopify.com/s/files/1/0435/3448/3605/files/lopepidemi.pdf
    • https://84d1550a-255b-4d30-b1cf-c174426c7e55.filesusr.com/ugd/696117_52ec98439a204ea9a5d88654fcc2da20.pdf?index=true
    • https://f9238c45-0fda-4e34-85d1-3e4af8cfdbd0.filesusr.com/ugd/60e703_7b0318f2f8a942b387d23b168a540d77.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0435/9720/1567/files/learn_german_with_stories_caf_in_berlin_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0430/2936/4889/files/ethiopian_grade_12_biology_text_book.pdf
    • https://cdn.shopify.com/s/files/1/0432/2436/7266/files/13_attributes_of_god_list.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004a38.bin
ea620530c4f5391746548c9734bca6b62923c24df2ef68e4975c897b48efeb14
pdf-font-stream PDF embedded font (sfnt) at offset 0x4A38 5264 bytes
font_01_sfnt_off00005c25.bin
3dd859bc19fd9f681812a5436522e67a39dae6dcfbeb6151acf40c51fbb7798c
pdf-font-stream PDF embedded font (sfnt) at offset 0x5C25 9048 bytes