Malicious PDF — malware analysis report

Static analysis result for SHA-256 9249f33b73926073…

MALICIOUS

PDF

47.6 KB Created: 2020-07-27 21:14:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a03aad3c14924ad8e1955963bec79de8 SHA-1: 6fca3461923674272d6676093f77093739373042 SHA-256: 9249f33b7392607373f074a72376382e89062def03e5da22f7fd2131cc16c79b
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to ttraff.com. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded links, many hosted on cdn.shopify.com. The ML classifier also strongly indicated maliciousness. The document body, though heavily obfuscated, contains text related to 'Image background react native android' and application metadata, suggesting a lure to disguise the malicious links.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=image+background+react+native+android
    • http://files.wickerdfarm.com/uploads/1/3/1/4/131407357/396206.pdf
    • http://files.antiquesatkimberton.com/uploads/1/3/1/6/131637135/kenoxiv_lugoxeb_zagugix.pdf
    • http://files.taichiwithxiaobo.com/uploads/1/3/2/8/132816096/zupufukefi.pdf
    • https://cdn.shopify.com/s/files/1/0438/4695/9261/files/fezov.pdf
    • https://cdn.shopify.com/s/files/1/0435/7101/9935/files/jafetuvo.pdf
    • https://cdn.shopify.com/s/files/1/0440/1335/5166/files/luwewaxofatawuwotos.pdf
    • https://cdn.shopify.com/s/files/1/0428/5900/4070/files/fawazamoxiburo.pdf
    • https://cdn.shopify.com/s/files/1/0431/5162/2306/files/9803600662.pdf
    • https://cdn.shopify.com/s/files/1/0430/1763/3949/files/62843058903.pdf
    • https://cdn.shopify.com/s/files/1/0430/6649/1041/files/12097089519.pdf
    • https://cdn.shopify.com/s/files/1/0431/5398/1594/files/93544088707.pdf
    • https://cdn.shopify.com/s/files/1/0431/9304/1053/files/63923411773.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/vevisip.pdf
    • https://cdn.shopify.com/s/files/1/0431/6522/1028/files/vikikafegefezevixes.pdf
    • https://cdn.shopify.com/s/files/1/0436/4389/5966/files/50134214624.pdf
    • https://cdn.shopify.com/s/files/1/0429/2981/5705/files/55399071369.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/52733892229.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com/s/files/1/0431/5162/2306/files/9803600

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007001.bin
9fd917cd3a04e4932322b2d337a53eb03504771de6bce9e9cc993b71f2d59c07
pdf-font-stream PDF embedded font (sfnt) at offset 0x7001 5132 bytes
font_01_sfnt_off00008154.bin
6d2a3a16cc464ce72cf05976c7f96a31c93af2202e0dc760c37a694345e222ee
pdf-font-stream PDF embedded font (sfnt) at offset 0x8154 1800 bytes
font_02_sfnt_off000089e4.bin
0ebe5c29bede38f304059fd08cae82454464574113a8282803c0cd253b569f2a
pdf-font-stream PDF embedded font (sfnt) at offset 0x89E4 11336 bytes