Malicious PDF — malware analysis report

Static analysis result for SHA-256 a74e0c8918798382…

MALICIOUS

PDF

58.0 KB Created: 2020-09-01 15:48:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1f0564596c25a4a921d5fe1c52fe04ef SHA-1: ecb2d174749cf6b640cd34ee7703b9d4847e6139 SHA-256: a74e0c89187983823a6383f81d45dde70289c8add9abd366d2584406f29d0d41
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.club/wix?keyword=chauka+kannada+movie+songs+free'. It also exhibits characteristics of a PDF link farm, with numerous embedded URLs. The document body, though heavily obfuscated, contains the same malicious URL, suggesting the primary intent is to redirect users to potentially harmful content under the guise of providing movie song links. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=chauka+kannada+movie+songs+free
    • https://static.usrfiles.com/ugd/bf650e_04fa8a9e26b943fda5609180f01fd74e.pdf
    • https://static.usrfiles.com/ugd/f0f215_d8470ab33ac647f59cecc19e1b5b62de.pdf
    • https://static.usrfiles.com/ugd/8d0191_be20b867d29a429fb1798f3edbe47b1a.pdf
    • https://static.usrfiles.com/ugd/824332_e38db97d126c491f82474872b34024f7.pdf
    • https://static.usrfiles.com/ugd/b8c837_754389c3fe49474483e0c5960eceea09.pdf
    • https://static.usrfiles.com/ugd/4117a9_d9522a12c96d4005a15190be6712c204.pdf
    • https://cdn.shopify.com/s/files/1/0435/3431/9776/files/torejifetamibuxevezed.pdf
    • https://cdn.shopify.com/s/files/1/0472/3166/4293/files/wawosiba.pdf
    • https://cdn.shopify.com/s/files/1/0429/5802/8959/files/file_sang_hnh_nh.pdf
    • https://cdn.shopify.com/s/files/1/0430/2022/2627/files/96581132980.pdf
    • https://static.usrfiles.com/ugd/b8c837_e21ac01d42b1456f88727182eb37006b.pdf
    • https://static.usrfiles.com/ugd/7d1dc9_6d20f2e8a65c4a689d7b2ddcb4575f5f.pdf
    • https://static.usrfiles.com/ugd/cf14a4_29bba09ed433484cab51daf9c873ae32.pdf
    • https://static.usrfiles.com/ugd/d8e941_d3454634e92e403eade024eff1f01bbf.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008ab1.bin
0ae0011958f1de16a5b3503cb44954c95853e86d571786277c301c06b6042d00
pdf-font-stream PDF embedded font (sfnt) at offset 0x8AB1 5316 bytes
font_01_sfnt_off00009ca3.bin
103a81cc9fe02e2ac1a55e848b1f767dc6308b47d5eb50d15b1014ad1e0fde25
pdf-font-stream PDF embedded font (sfnt) at offset 0x9CA3 12924 bytes
font_02_sfnt_off0000c5a3.bin
e296a61d2d303e35be9e1a35631556663d2780498efa7e8f3867bf557f172fe6
pdf-font-stream PDF embedded font (sfnt) at offset 0xC5A3 16164 bytes