Malicious PDF — malware analysis report

Static analysis result for SHA-256 2dd03401df81c3f3…

MALICIOUS

PDF

48.5 KB Created: 2020-08-25 04:38:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b6b83559b0c63eb5917f2d042796aa02 SHA-1: 09c5bfbbb85ec2cff41f8aa4edd5a81e05f3bfdf SHA-256: 2dd03401df81c3f3254d9ffa29b04b83f0347bb6741e3aae0c3a6e4a02b538ad
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. Additionally, it features a PDF link farm heuristic, indicating a large number of external links, with the first being to 'cdn.shopify.com'. The ML classifier also strongly flagged this PDF as malicious. The document body contains text related to 'Aura sync msi', likely a lure to entice users to click the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=aura+sync++msi
    • http://files.ctsulianah.com/uploads/1/3/1/4/131409090/mexudexalafelumul.pdf
    • http://files.somosescritores.com/uploads/1/3/0/8/130813054/metagaxinevakuk.pdf
    • http://files.oakwoodvethospital.com/uploads/1/3/1/4/131438038/3742043.pdf
    • http://files.coltsound.com/uploads/1/3/1/3/131398526/zonobowojel.pdf
    • https://cdn.shopify.com/s/files/1/0438/6557/1493/files/rawitarasovi.pdf
    • https://cdn.shopify.com/s/files/1/0429/1035/1513/files/40271384351.pdf
    • https://cdn.shopify.com/s/files/1/0436/8944/3483/files/free_new_punjabi_audio_song.pdf
    • https://cdn.shopify.com/s/files/1/0437/6425/2826/files/mugijikawasatebelezolixo.pdf
    • https://cdn.shopify.com/s/files/1/0434/0698/3335/files/9474682690.pdf
    • https://cdn.shopify.com/s/files/1/0430/0580/4698/files/vixesog.pdf
    • https://cdn.shopify.com/s/files/1/0429/2637/5071/files/castle_crashers_best_weapon.pdf
    • https://cdn.shopify.com/s/files/1/0435/5594/6645/files/zuwerikunesoziz.pdf
    • https://cdn.shopify.com/s/files/1/0431/9599/0175/files/nigger_owners_manual.pdf
    • https://cdn.shopify.com/s/files/1/0431/5247/4267/files/64294050689.pdf
    • https://cdn.shopify.com/s/files/1/0431/5847/0816/files/nivati.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000596b.bin
e1c3a03f5dbbbc358386757a3633c3a000ae7d89e4ee44558aefacab65cdca4d
pdf-font-stream PDF embedded font (sfnt) at offset 0x596B 4580 bytes
font_01_sfnt_off000068c3.bin
3a83cc9b205ba5a818139ea35497bbd2757f703e99bfd783c939bb2d8891f263
pdf-font-stream PDF embedded font (sfnt) at offset 0x68C3 12624 bytes
font_02_sfnt_off00009173.bin
684a3c196e802b4dc45ee85e0d12f41c83d6b6c6a55a83cec5fb8e332ee9aa36
pdf-font-stream PDF embedded font (sfnt) at offset 0x9173 16376 bytes
font_03_sfnt_off0000a71b.bin
ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3
pdf-font-stream PDF embedded font (sfnt) at offset 0xA71B 4324 bytes