Malicious PDF — malware analysis report

Static analysis result for SHA-256 2c8cf4c32495e287…

MALICIOUS

PDF

56.9 KB Created: 2020-08-15 00:26:43 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 01f44519d4ecb594d772a8a335da430d SHA-1: 14fd31421be21bd799213eb6b6c66881178c769a SHA-256: 2c8cf4c32495e287bfe151a5ca2cce5c6b4df3a0aa5b786b5ef4af9907a88289
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://ttraff.com/pify?keyword=marathi+bhajan+free++audio'. Additionally, it exhibits a PDF link farm behavior, with numerous links pointing to external PDFs, many hosted on Shopify. The ML classifier also strongly indicated maliciousness. The document body, though heavily obfuscated, contains the redirector URL, suggesting a lure to disguise malicious activity.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=marathi+bhajan+free++audio
    • http://files.tewksburybaptists.org/uploads/1/3/2/7/132711975/22d93687114.pdf
    • http://files.motorcyclesafetyprogram.org/uploads/1/3/2/6/132695493/9a5160ad581f88.pdf
    • http://files.radianace.com/uploads/1/3/1/0/131070722/da7b8d58b7890f6.pdf
    • http://files.mrsberthaosclassroom.com/uploads/1/3/0/7/130740264/d3b77554683.pdf
    • https://cdn.shopify.com/s/files/1/0438/9273/6155/files/xumutitobekewedotu.pdf
    • https://cdn.shopify.com/s/files/1/0428/6775/3116/files/83431095057.pdf
    • https://cdn.shopify.com/s/files/1/0431/5788/0996/files/cal_poly_campus_map.pdf
    • https://cdn.shopify.com/s/files/1/0436/5818/2809/files/teori_utilitarianisme_jeremy_bentham_pdf.pdf
    • https://cdn.shopify.com/s/files/1/0432/6552/3862/files/makalah_agama_islam_tentang_zakat.pdf
    • https://cdn.shopify.com/s/files/1/0429/3450/1535/files/basevebiwezurigomawoxurup.pdf
    • https://cdn.shopify.com/s/files/1/0430/6773/6225/files/xipukasamejogapugagiv.pdf
    • https://cdn.shopify.com/s/files/1/0433/6130/4728/files/64464405069.pdf
    • https://cdn.shopify.com/s/files/1/0431/6430/3522/files/80343781156.pdf
    • https://cdn.shopify.com/s/files/1/0430/2408/9242/files/56837737886.pdf
    • https://cdn.shopify.com/s/files/1/0430/0265/8979/files/building_technology_3.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com/s/files/1/0431/6430/3522/files/8

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000083ad.bin
b97bfbdee499f9f35235b6026b62ec455e99406f481285591d8ffd9c149f982d
pdf-font-stream PDF embedded font (sfnt) at offset 0x83AD 5004 bytes
font_01_sfnt_off000094b2.bin
5d2e0a6f13ca6d4b9204228ffe377a80f3c7d12842bf7e74716d0ba51f258f95
pdf-font-stream PDF embedded font (sfnt) at offset 0x94B2 14264 bytes
font_02_sfnt_off0000c17f.bin
541fa2b6826b0add99b7d5a173ef1e6a5567607b5192f75b810eb17d6a563501
pdf-font-stream PDF embedded font (sfnt) at offset 0xC17F 16204 bytes