Malicious PDF — malware analysis report

Static analysis result for SHA-256 a895833bd907671d…

MALICIOUS

PDF

41.7 KB Created: 2020-08-25 03:07:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bd975e6dc48a02a4b1c1df9b3d9d7782 SHA-1: ccb826eb77d8b4bd1923df10f14f4af9caad4bf1 SHA-256: a895833bd907671d8d8113884cd6781c538754522b8ba67b545e4455e72b7c41
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link farm designed to manipulate search engine results, directing users to a malicious redirector. The primary malicious URL identified is https://ttraff.cc/pify?keyword=kenapa+google+play+store++pending, which is likely used to lure victims into downloading further malware or visiting phishing pages. The ML classifier strongly indicated maliciousness, and the PDF structure itself is suspicious due to the mass of external links.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=kenapa+google+play+store++pending
    • http://files.jennifercrowderartist.com/uploads/1/3/2/7/132740249/sajajekofome_vusove_tagamitezejiwa.pdf
    • http://pesukuw.infusingcomputing.com/uploads/1/3/1/4/131453850/f0df386e4d2fe2a.pdf
    • http://xilap.capitalstringing.com/uploads/1/3/1/0/131071021/5324673.pdf
    • https://cdn.shopify.com/s/files/1/0434/6219/7400/files/xikamubilegafiz.pdf
    • https://cdn.shopify.com/s/files/1/0450/0642/2184/files/manevixino.pdf
    • https://cdn.shopify.com/s/files/1/0430/4686/3005/files/41393669344.pdf
    • https://cdn.shopify.com/s/files/1/0438/0445/9170/files/wusudogifalasibikeju.pdf
    • https://cdn.shopify.com/s/files/1/0431/0263/4148/files/netujo.pdf
    • https://cdn.shopify.com/s/files/1/0434/3303/3880/files/5560459379.pdf
    • https://cdn.shopify.com/s/files/1/0429/6019/1641/files/vupenof.pdf
    • https://cdn.shopify.com/s/files/1/0428/5107/4214/files/53554250932.pdf
    • https://cdn.shopify.com/s/files/1/0432/5313/7576/files/mavugugejakudatopimevaz.pdf
    • https://cdn.shopify.com/s/files/1/0437/4609/9349/files/java_interview_questions_and_answers_download.pdf
    • https://cdn.shopify.com/s/files/1/0431/4673/9866/files/nelinalajiwoxafifalogat.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005ee7.bin
896b3e3397f4804d55647eb9557202c8f329bae6fcb9dc0b61121700fdd37c8d
pdf-font-stream PDF embedded font (sfnt) at offset 0x5EE7 5200 bytes
font_01_sfnt_off000070ad.bin
7c083f2ac2cfe9d679f1eb028c560cc086229165f74df919068df55fc87d31e6
pdf-font-stream PDF embedded font (sfnt) at offset 0x70AD 12992 bytes