Malicious PDF — malware analysis report

Static analysis result for SHA-256 a48ea337c140096e…

MALICIOUS

PDF

41.6 KB Created: 2020-08-03 02:54:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: be73a02b068184042721a635aafe3c5f SHA-1: 9abdfdf845adbb574c679c800cac6f4912d321f1 SHA-256: a48ea337c140096edf4addec9810c369e78e9fe5bce69386b436f9fae0d00495
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, with the primary redirector URL being ttraff.com. This indicates a link farm or redirection scheme designed to lead users to potentially malicious content. The ML classifier strongly supports the malicious nature of this PDF. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=wow+classic+cask+of+merlot
    • http://files.afpinball.com/uploads/1/3/0/7/130775979/5892714.pdf
    • http://files.astrologervaranasi.com/uploads/1/3/2/6/132682134/nagas_dekexibodevarus.pdf
    • http://files.preraktrust.org/uploads/1/3/1/8/131871952/95d2fd1ec.pdf
    • http://files.harrishomeopathy.com/uploads/1/3/1/3/131398091/742490.pdf
    • https://cdn.shopify.com/s/files/1/0437/8941/8657/files/sukeviwizi.pdf
    • https://cdn.shopify.com/s/files/1/0430/8362/8697/files/vizidalagibokero.pdf
    • https://cdn.shopify.com/s/files/1/0427/7728/0671/files/11654446407.pdf
    • https://cdn.shopify.com/s/files/1/0431/6925/1487/files/sezadukuvinasemo.pdf
    • https://cdn.shopify.com/s/files/1/0428/0736/1703/files/nibuk.pdf
    • https://cdn.shopify.com/s/files/1/0429/2821/0073/files/nerapusimobezaro.pdf
    • https://cdn.shopify.com/s/files/1/0431/8851/9080/files/jojowisine.pdf
    • https://cdn.shopify.com/s/files/1/0428/2348/3548/files/10_000_days_in_years.pdf
    • https://cdn.shopify.com/s/files/1/0432/3006/8898/files/vunudivixizadedo.pdf
    • https://cdn.shopify.com/s/files/1/0433/6756/3429/files/28192218526.pdf
    • https://cdn.shopify.com/s/files/1/0433/1238/2117/files/nogenedifomijifunitakol.pdf
    • https://cdn.shopify.com/s/files/1/0435/4700/0983/files/17126722495.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006155.bin
2ca8428d6502c3a0b48418cbe9a6b000045d0f70b2b2b01bf70146ed3ec96574
pdf-font-stream PDF embedded font (sfnt) at offset 0x6155 5196 bytes
font_01_sfnt_off0000730a.bin
b6af75f3b0e778918826b5457475ceb95a4fec3af7326ce24bdbf2bdfd1b3ba8
pdf-font-stream PDF embedded font (sfnt) at offset 0x730A 11720 bytes