Malicious PDF — malware analysis report

Static analysis result for SHA-256 798ccfc4eb4a309d…

MALICIOUS

PDF

147.4 KB Created: 2020-08-05 04:47:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 19008de8d0dd793b6eb25cc6600cfac7 SHA-1: b054037c69c59cf8fc97cd968aa39115406ae7d3 SHA-256: 798ccfc4eb4a309da8cd6cd769eefbc6251e2ea82e248b927d0817924c5417cd
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a critical heuristic firing indicating a link to known malicious redirector infrastructure. The embedded URL 'https://ttraff.com/pify?keyword=aqeedah+english+pdf' is directly associated with this malicious activity. The ML classifier also strongly flagged this PDF as malicious. The document body, though heavily obfuscated, appears to contain the malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=aqeedah+english+pdf
    • http://kufaf.americanawningabc.com/uploads/1/3/2/6/132681504/88c52b7a8.pdf
    • http://files.marblefallslibrarythrift.com/uploads/1/3/1/3/131398560/bidavubupenot.pdf
    • http://files.parker-co.com/uploads/1/3/0/8/130874119/9178c75b.pdf
    • https://cdn.shopify.com/s/files/1/0429/9898/8949/files/leduzejob.pdf
    • https://cdn.shopify.com/s/files/1/0428/3547/6636/files/39263283463.pdf
    • https://cdn.shopify.com/s/files/1/0427/9717/0847/files/nolezogi.pdf
    • https://cdn.shopify.com/s/files/1/0432/7201/1931/files/ridubuzoge.pdf
    • https://cdn.shopify.com/s/files/1/0431/5096/6950/files/69817085529.pdf
    • https://cdn.shopify.com/s/files/1/0431/6954/6395/files/49634797199.pdf
    • https://cdn.shopify.com/s/files/1/0434/3860/4450/files/konekokimitizikolutak.pdf
    • https://cdn.shopify.com/s/files/1/0432/8924/7894/files/fexijufok.pdf
    • https://cdn.shopify.com/s/files/1/0428/3265/8588/files/76872996101.pdf
    • https://cdn.shopify.com/s/files/1/0438/4423/9510/files/94094931192.pdf
    • https://cdn.shopify.com/s/files/1/0429/8326/0314/files/63014658147.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off000204c8.bin
e09db82676f40431b86d336669da0e928cfa139b56e8f388ac57d57b8ae98929
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x204C8 34672 bytes
font_00_sfnt_off0001cd82.bin
cf8ef421d6cb4de1914b587e7aa1b670c3eb2bb65280219beaf4db0074218b33
pdf-font-stream PDF embedded font (sfnt) at offset 0x1CD82 5320 bytes
font_01_sfnt_off0001df9a.bin
9de7a45f0bb44454f206c43ae3f696b545eb128a686469d6378a734385445532
pdf-font-stream PDF embedded font (sfnt) at offset 0x1DF9A 11856 bytes