Malicious PDF — malware analysis report

Static analysis result for SHA-256 2caf01e4cbad1553…

MALICIOUS

PDF

45.3 KB Created: 2020-07-27 05:13:41 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 97ea1ef33f37148b5c187d0d32f30354 SHA-1: a66c4d7c2d02149798cde339b18f5f3c56217781 SHA-256: 2caf01e4cbad15539b817549b7c108a89105f2ad8fc7eb7fa3c87d2a9fdae892
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link to a known malicious redirector, ttraff.com, which is designed to lure users into downloading potentially malicious content. The document body, though heavily obfuscated, contains text related to 'Picsart mod apk new version', suggesting a social engineering pretext for the malicious link. The presence of numerous external PDF links, many hosted on Shopify, further indicates a link farm designed to attract search engine traffic and distribute malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=picsart+mod+apk+new+version
    • http://files.flatspokecycles.com/uploads/1/3/1/4/131408529/6549756.pdf
    • http://files.rescuecandlewoodmountain.org/uploads/1/3/0/7/130775837/b09b9cb.pdf
    • http://files.chillypepper.org/uploads/1/3/0/7/130775393/lesapokox-seraxuti-sipanawudega.pdf
    • http://files.mycountyparks.org/uploads/1/3/1/4/131483371/377691.pdf
    • http://files.jcrvtx.com/uploads/1/3/1/3/131398066/831f4a67168.pdf
    • http://files.rescuecandlewo
    • https://cdn.shopify.com/s/files/1/0431/8239/1451/files/51439341050.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/42778697636.pdf
    • https://cdn.shopify.com/s/files/1/0431/7151/2480/files/34198354094.pdf
    • https://cdn.shopify.com/s/files/1/0427/6623/7852/files/nawonevatonufabomugikesi.pdf
    • https://cdn.shopify.com/s/files/1/0436/8993/5003/files/logosamidu.pdf
    • https://cdn.shopify.com/s/files/1/0431/5345/7320/files/10358872556.pdf
    • https://cdn.shopify.com/s/files/1/0429/3584/5017/files/lemutovetike.pdf
    • https://cdn.shopify.com/s/files/1/0434/9480/1568/files/rovexikaxonogeropapozafoz.pdf
    • https://cdn.shopify.com/s/files/1/0432/1024/4256/files/kafuxemojumegudulojevik.pdf
    • https://cdn.shopify.com/s/files/1/0433/2371/9845/files/danusowavabigiladurikidis.pdf
    • https://cdn.shopify.com/s/files/1/0431/4575/6821/files/tolixonolekufe.pdf
    • https://cdn.shopify.com/s/files/1/0428/9619/5737/files/vowosaveselud.pdf
    • https://cdn.shopify.com/s/files/1/0434/7399/3890/files/16942128656.pdf
    • https://cdn.shopify.com/s/files/1/0428/3239/6447/files/25399217636.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007480.bin
fa3e280e908f09aa1a0a001bda49a07e6a80f5a5c9d213f5dd969f1058601bf7
pdf-font-stream PDF embedded font (sfnt) at offset 0x7480 5192 bytes
font_01_sfnt_off00008620.bin
df45da99031b901648c1f20c755b29837cbc7d7c743391197770c98887f358e7
pdf-font-stream PDF embedded font (sfnt) at offset 0x8620 9924 bytes