Malicious PDF — malware analysis report

Static analysis result for SHA-256 35becdf757c74aff…

MALICIOUS

PDF

43.5 KB Created: 2020-08-02 22:24:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fd756e53be641b90fc0580e310464d4f SHA-1: cc26aacf5808393e14072aaeb5490e3fbf6d232f SHA-256: 35becdf757c74affd97cf2fae9754f53d1bd1d96a3469cbc1ff13c4d5967a129
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, many of which point to Shopify domains hosting other PDFs, forming a link farm. One critical heuristic identified a link to a known malicious redirector at 'https://ttraff.com/pify?keyword=dvd+video+soft'. This suggests the document's primary purpose is to redirect users to malicious infrastructure, likely for further exploitation or phishing. No scripts were extracted, and the document body was heavily obfuscated.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=dvd+video+soft
    • http://files.becksusedappliances.com/uploads/1/3/1/6/131606325/7514694.pdf
    • http://files.jodirenshaw.com/uploads/1/3/1/4/131407974/250d8a2e2.pdf
    • http://files.papayabranchboutique.com/uploads/1/3/1/4/131482819/405acc38c2.pdf
    • http://files.virgiliumidrigan.com/uploads/1/3/0/7/130740444/rilopo.pdf
    • http://files.carambola.ie/uploads/1/3/1/3/131383325/7535349.pdf
    • https://cdn.shopify.com/s/files/1/0437/1021/8391/files/64122568738.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/11783771814.pdf
    • https://cdn.shopify.com/s/files/1/0435/7092/1635/files/83063221514.pdf
    • https://cdn.shopify.com/s/files/1/0433/6893/9672/files/4053599924.pdf
    • https://cdn.shopify.com/s/files/1/0432/8787/1646/files/11569991745.pdf
    • https://cdn.shopify.com/s/files/1/0441/0834/9592/files/saluxife.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/sosivizugepu.pdf
    • https://cdn.shopify.com/s/files/1/0429/8126/1466/files/48760297689.pdf
    • https://cdn.shopify.com/s/files/1/0432/3203/4980/files/foxof.pdf
    • https://cdn.shopify.com/s/files/1/0427/9864/5404/files/84143190040.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006e1e.bin
c12f8f5ea7bff2c7cb91aa87daeaec773a31791c0b35b7fa5b1c4b398eb9ee4b
pdf-font-stream PDF embedded font (sfnt) at offset 0x6E1E 4624 bytes
font_01_sfnt_off00007e00.bin
699122129729e6b189453c9e40ce48a663de3bcffef90b01aa8cb5d30954f461
pdf-font-stream PDF embedded font (sfnt) at offset 0x7E00 10484 bytes