Malicious PDF — malware analysis report

Static analysis result for SHA-256 aa1d31a49a67388d…

MALICIOUS

PDF

40.7 KB Created: 2020-08-20 06:53:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2dbe329e0b445419308c71ede3a160c0 SHA-1: ed6dcdb84d3e42e84b458ab0268923bd50bc6e33 SHA-256: aa1d31a49a67388de6bc6901d269e6a901a73f6c7f136362741d9f7eafdfd60a
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a significant number of embedded links, identified as a PDF link farm. The primary malicious URL, https://ttraff.com/pify?keyword=business+card+maker+android+github, is a known redirector. This suggests the document's purpose is to lure users into clicking these links, which likely lead to phishing pages or malware downloads. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=business+card+maker+android+github
    • http://files.ninacoffaro.com/uploads/1/3/1/6/131637374/levibapod.pdf
    • https://cdn.shopify.com/s/files/1/0431/1190/7488/files/kenmore_70_series_washer_parts.pdf
    • https://cdn.shopify.com/s/files/1/0437/5497/9477/files/fluvial_processes_in_geomorphology.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/vunumegosuvuvorewufo.pdf
    • https://cdn.shopify.com/s/files/1/0431/5866/7415/files/78753134693.pdf
    • https://cdn.shopify.com/s/files/1/0438/2241/6029/files/dizopalusuzedodipojosa.pdf
    • https://cdn.shopify.com/s/files/1/0432/8806/8254/files/tavenozopasug.pdf
    • https://cdn.shopify.com/s/files/1/0429/1310/4035/files/biposudabenepo.pdf
    • https://cdn.shopify.com/s/files/1/0428/6559/0438/files/vevavune.pdf
    • https://cdn.shopify.com/s/files/1/0432/2210/6271/files/dopirejuluvamogepodoxokos.pdf
    • https://cdn.shopify.com/s/files/1/0431/4379/0760/files/95280435077.pdf
    • https://cdn.shopify.com/s/files/1/0431/0692/6741/files/2511118985.pdf
    • https://cdn.shopify.com/s/files/1/0436/9540/7269/files/sobijuzutimo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000610c.bin
97d0309e4062783290caa07f5e4ddb536e57262bc8f07a3d8787093237049a77
pdf-font-stream PDF embedded font (sfnt) at offset 0x610C 5576 bytes
font_01_sfnt_off000073cc.bin
1543c85e29455031a88023c18ea506d313726827144fe7fc77d19dc1407276b7
pdf-font-stream PDF embedded font (sfnt) at offset 0x73CC 10024 bytes