Malicious PDF — malware analysis report

Static analysis result for SHA-256 aee9c47207fa2bae…

MALICIOUS

PDF

42.9 KB Created: 2020-08-04 19:20:28 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: afb446f6ea05aa065cf606267e7ae8d4 SHA-1: 600090dfb6969bce15bf86c7755f3b6368f107ac SHA-256: aee9c47207fa2bae6811673ad816703974925d8e53a2056623099eeae9427df6
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a link farm and a critical redirector link pointing to ttraff.cc, indicating a phishing or redirection attempt. The document body, though partially corrupted, includes the target URL and a keyword suggesting a lure for downloading Algerian newspapers. The presence of numerous external links, many hosted on Shopify, further supports the link farm heuristic. No scripts were extracted, but the primary attack vector appears to be social engineering via a malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=telecharger+les+journaux+algeriens+en+pdf+gratuit
    • http://files.maryellenallison.com/uploads/1/3/0/7/130776164/940183c1a.pdf
    • http://files.theroverchasefoundation.com/uploads/1/3/1/0/131069887/baxelovinu_nozuxuduzas_fagezuxurumimav_laleb.pdf
    • http://files.littleexplorerschildminding.com/uploads/1/3/0/7/130776745/jozojuf.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/74535711799.pdf
    • https://cdn.shopify.com/s/files/1/0431/8176/8864/files/rekemadinowusifukafiwu.pdf
    • https://cdn.shopify.com/s/files/1/0431/7465/8216/files/80594265675.pdf
    • https://cdn.shopify.com/s/files/1/0430/1396/3935/files/zajinawotifexidej.pdf
    • https://cdn.shopify.com/s/files/1/0431/4457/7185/files/acs_chemistry_study_guide.pdf
    • https://cdn.shopify.com/s/files/1/0432/4956/5853/files/96206886435.pdf
    • https://cdn.shopify.com/s/files/1/0432/5385/8472/files/79625380981.pdf
    • https://cdn.shopify.com/s/files/1/0431/9028/8535/files/mabelub.pdf
    • https://cdn.shopify.com/s/files/1/0429/6137/1290/files/gekigunepubexarariwa.pdf
    • https://cdn.shopify.com/s/files/1/0432/5556/2402/files/redarad.pdf
    • https://cdn.shopify.com/s/files/1/0436/7984/2457/files/teburaropiga.pdf
    • https://cdn.shopify.com/s/files/1/0430/0803/2922/files/12381481209.pdf
    • https://cdn.shopify.com/s/files/1/0434/0485/3406/files/bejexelomorobokuw.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004f6f.bin
cbadc8f63dbd8a28f8bed1701bc23a673be38ae81f3e90686fa020b2a9e5f682
pdf-font-stream PDF embedded font (sfnt) at offset 0x4F6F 5512 bytes
font_01_sfnt_off00006235.bin
095b8dbb21fe8d4d39127b2a1ebbe0dc7996c76261a04a0b62d832fb24eb85fb
pdf-font-stream PDF embedded font (sfnt) at offset 0x6235 11364 bytes
font_02_sfnt_off000086c6.bin
b164a17a147321d702d2b0bd394a336534949b91aef060492947284c427dd056
pdf-font-stream PDF embedded font (sfnt) at offset 0x86C6 16312 bytes