Malicious PDF — malware analysis report

Static analysis result for SHA-256 56dc280fdd376068…

MALICIOUS

PDF

68.4 KB Created: 2020-08-23 02:49:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 02c7e1141a8ec0f2eab87bfb301ac44b SHA-1: b1fa3613bc7d0b70458ac0b8850a9d650084d9ba SHA-256: 56dc280fdd376068de18545243708a22ae51444e8b8a865dbfcd517d5d2ea968
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic indicating it links to known malicious redirector infrastructure, specifically pointing to 'ttraff.com'. The document body, though heavily obfuscated, also contains this URL and references keywords like 'android python 3d game engine', suggesting a lure. The presence of a large number of external PDF links, many hosted on Shopify, further supports the idea of a link farm designed to attract traffic. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=android+python+3d+game+engine
    • http://files.cascadefactoryhomes.com/uploads/1/3/1/4/131408369/8813715.pdf
    • https://cdn.shopify.com/s/files/1/0432/4062/0200/files/bovine_viral_diarrhea.pdf
    • https://cdn.shopify.com/s/files/1/0437/5219/4202/files/barbara_cartland_ebooks_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/logopazunu.pdf
    • https://cdn.shopify.com/s/files/1/0437/8315/9969/files/bipitivonebiludon.pdf
    • https://cdn.shopify.com/s/files/1/0440/6162/2437/files/sazuxaw.pdf
    • https://cdn.shopify.com/s/files/1/0446/4807/1331/files/ncert_exemplar_class_12_maths.pdf
    • https://cdn.shopify.com/s/files/1/0431/0165/1105/files/773_951_7670.pdf
    • https://cdn.shopify.com/s/files/1/0438/1143/8752/files/icao_annex_17_free_download.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c1f7.bin
45096d4adfc367ae71d3dee0b276e01e6b1644b3a42f1213b73859252f5d1a47
pdf-font-stream PDF embedded font (sfnt) at offset 0xC1F7 5416 bytes
font_01_sfnt_off0000d440.bin
4c7dd169105d2320e9e449555f8334f0aad7588879f18876dfaa7ffd80387321
pdf-font-stream PDF embedded font (sfnt) at offset 0xD440 15876 bytes