Malicious PDF — malware analysis report

Static analysis result for SHA-256 492fbf704bb68c96…

MALICIOUS

PDF

70.1 KB Created: 2020-08-16 15:04:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9973063843d9dc4ff838144f3464c7b6 SHA-1: d28ece1b93d37ca9a18d8ec053d4fde8f4f3f4bd SHA-256: 492fbf704bb68c96ecb27674a3d5e61f68ff908b9161b563d4d4c523877671e8
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous embedded links, a common tactic for SEO link farms and redirector schemes. One critical heuristic identified a link to a known malicious redirector infrastructure at 'https://ttraff.com/pify?keyword=doraemon+dorabian+nights+full+movie'. The document body, though heavily obfuscated, also contains this URL, suggesting the primary intent is to lure users to this malicious site. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=doraemon+dorabian+nights+full+movie
    • http://files.perfect-peace.com/uploads/1/3/1/0/131069934/7afc2bb38bb69.pdf
    • http://xenib.golcarlilyday.co.uk/uploads/1/3/0/8/130874493/sakudeti-gutojotafavit-vematetitafaz.pdf
    • http://files.kellymartinbooks.com/uploads/1/3/1/4/131454102/juwot.pdf
    • http://vababex.mcmillencompany.com/uploads/1/3/0/7/130775350/53072c44bb6e.pdf
    • https://cdn.shopify.com/s/files/1/0431/9775/9643/files/11645668526.pdf
    • https://cdn.shopify.com/s/files/1/0431/5011/4965/files/a_b_z_forms_of_dna.pdf
    • https://cdn.shopify.com/s/files/1/0440/8298/7173/files/37598433739.pdf
    • https://cdn.shopify.com/s/files/1/0431/3566/4284/files/inequality_worksheet_7th_grade.pdf
    • https://cdn.shopify.com/s/files/1/0430/7651/8049/files/73621003866.pdf
    • https://cdn.shopify.com/s/files/1/0433/2571/8678/files/pesokilamawolagitini.pdf
    • https://cdn.shopify.com/s/files/1/0438/0668/7389/files/48090831413.pdf
    • https://cdn.shopify.com/s/files/1/0427/7082/5382/files/pdf_biology_class_11_notes.pdf
    • https://cdn.shopify.com/s/files/1/0435/8150/5695/files/52510357240.pdf
    • https://cdn.shopify.com/s/files/1/0437/7106/8565/files/tosofamorutepebox.pdf
    • https://cdn.shopify.com/s/files/1/0427/5650/5756/files/talijopaboliluxibita.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005f8e.bin
b6daed545f06881b2c5196d5a3e0ab4a9ec3e243f49abf7721e32927acc1961c
pdf-font-stream PDF embedded font (sfnt) at offset 0x5F8E 11100 bytes
font_01_sfnt_off0000845d.bin
f69ff9d9e3d410064c024f5930c2a05f190341cf918f471208e9c4d1fae612f4
pdf-font-stream PDF embedded font (sfnt) at offset 0x845D 5520 bytes
font_02_sfnt_off000096f0.bin
b93616379e241b7432f8759c5ebd93bc7d410bfa68620d7f40af15db8fd3145f
pdf-font-stream PDF embedded font (sfnt) at offset 0x96F0 9364 bytes
font_03_sfnt_off0000b121.bin
af8fecb17fc431db3389aeb727edc98c5f2110d063043fc7491838f818bb1783
pdf-font-stream PDF embedded font (sfnt) at offset 0xB121 9956 bytes
font_04_sfnt_off0000d379.bin
46cf6267c82ac8f48613aa10bfaa4f1955d4d5a40f2a1a7713663691a020b06f
pdf-font-stream PDF embedded font (sfnt) at offset 0xD379 17324 bytes
font_05_sfnt_off0000ecd1.bin
d46dd180b27a455ac08fce41a3bf7711dab5630446cba26b94a6097d724017d5
pdf-font-stream PDF embedded font (sfnt) at offset 0xECD1 8772 bytes