Malicious PDF — malware analysis report

Static analysis result for SHA-256 a4b397d3cf5542fb…

MALICIOUS

PDF

41.1 KB Created: 2020-08-30 03:57:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 99c4cf1ba9a5e91f5377133802b2b069 SHA-1: 321ebb812161b771228dd6bb7538bbb31e613fc8 SHA-256: a4b397d3cf5542fb02cdcd8d0ee45c073d1de5340a67c101f60108b3d1b4b2c2
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/wix?keyword=kingdom%253A+new+lands+royal+edition'. The document body, though heavily obfuscated, contains references to 'Kingdom: new lands royal edition' and the malicious URL, suggesting a lure to a fake game or software download. The PDF also exhibits characteristics of a link farm, with numerous embedded links, many pointing to Shopify domains, but the primary malicious intent appears to be the redirector. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=kingdom%253A+new+lands+royal+edition
    • https://cdn.shopify.com/s/files/1/0429/1903/5033/files/42733067383.pdf
    • https://cdn.shopify.com/s/files/1/0430/8933/0330/files/nested_for_loops_javascript.pdf
    • https://cdn.shopify.com/s/files/1/0438/8130/0123/files/31655748887.pdf
    • https://cdn.shopify.com/s/files/1/0427/8992/9116/files/tukinebutemivemisejo.pdf
    • https://cdn.shopify.com/s/files/1/0428/2161/5775/files/nasabibodugadirebiveba.pdf
    • https://static.usrfiles.com/ugd/a86d68_ea78c4d2c2a4479e9a9762d540708370.pdf
    • https://static.usrfiles.com/ugd/eaf48f_c65480855d644eca9b61381ec77cb53a.pdf
    • https://static.usrfiles.com/ugd/12dc78_df465ec70e2f475aa10b428e53ee0704.pdf
    • https://static.usrfiles.com/ugd/7baf93_a02d8abfef324f1caa8d0fe9cd66fb07.pdf
    • https://static.usrfiles.com/ugd/e2b09b_aa53ebd962624083881f4907fec7a559.pdf
    • https://static.usrfiles.com/ugd/b8c837_3423be792ee54b759835f1d68b388df1.pdf
    • https://static.usrfiles.com/ugd/b8c837_b5dee72b39b8427087733b168de09a7f.pdf
    • https://static.usrfiles.com/ugd/1e32c2_76771a50ec394b57bfb98bc4cd0a18ee.pdf
    • https://static.usrfiles.com/ugd/314c35_343147ee7b2e4d7db4c8bf0d10e2f34c.pdf
    • https://static.usrfiles.com/ugd/2b25b5_7085a0ec6f3d41538b3736cc68aa1ee2.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000050f0.bin
91c30e2d1ada78d216450f988df81a9b8af68f06a1eabed5d87816fe5ae9965c
pdf-font-stream PDF embedded font (sfnt) at offset 0x50F0 3352 bytes
font_01_sfnt_off00005cef.bin
75abe8cccbcb5e7e31779bf483a3b2b2c243d2c891e9557e20a2749423c512c0
pdf-font-stream PDF embedded font (sfnt) at offset 0x5CEF 5360 bytes
font_02_sfnt_off00006f22.bin
7a31672d0034836e9de9c24d507eb3456ab0c00efab1b5a3f220ccd71aa3a57d
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F22 12592 bytes