Malicious PDF — malware analysis report

Static analysis result for SHA-256 b101432c517ff511…

MALICIOUS

PDF

38.2 KB Created: 2020-09-02 00:40:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f56f98b6bc96a923236889978a6a758c SHA-1: 4e3568489d2e4ad854b9a92628c0d889a4d3179b SHA-256: b101432c517ff511ac25e99c29cad69675270c55d6e149f0a3c43e639e4e79b8
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link to a known malicious redirector, ttraff.com, which is disguised with a keyword related to 'Singtel cast apk'. The document also exhibits characteristics of a link farm, with numerous embedded links to Shopify and usrfiles.com domains, likely intended to obscure the malicious destination. The ML classifier strongly flagged this PDF as malicious, supporting the assessment of a malicious redirector attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=singtel+cast+apk
    • https://cdn.shopify.com/s/files/1/0440/4730/2806/files/nugolewekezufopewum.pdf
    • https://cdn.shopify.com/s/files/1/0433/1434/8197/files/30345960752.pdf
    • https://cdn.shopify.com/s/files/1/0463/9650/6267/files/10886073049.pdf
    • https://cdn.shopify.com/s/files/1/0438/7926/8520/files/fawimuzeviduvixudokelujop.pdf
    • https://cdn.shopify.com/s/files/1/0431/1390/6327/files/tatafomebibinopodogus.pdf
    • https://cdn.shopify.com/s/files/1/0428/4992/7327/files/cake_emoji_android.pdf
    • https://static.usrfiles.com/ugd/b8c837_b2268c67d24c4265bb982ea2c21c768a.pdf
    • https://static.usrfiles.com/ugd/769f78_72f5094380464768951d84acdf1faf13.pdf
    • https://static.usrfiles.com/ugd/b8c837_529e85e8eafa4c27acd767bef33f89b5.pdf
    • https://static.usrfiles.com/ugd/277b62_35e264fdf035488fa08b5b49b0818bde.pdf
    • https://static.usrfiles.com/ugd/a4d998_a13f2d7bfcd1401e8bea575479396b2b.pdf
    • https://static.usrfiles.com/ugd/ef7486_607a15948919462db18a196446dc36f2.pdf
    • https://static.usrfiles.com/ugd/affaa6_69f96992ad014435936ac2634c6f02f9.pdf
    • https://static.usrfiles.com/ugd/26938b_2c545b97891e426f9b456fcdfcc078e3.pdf
    • https://static.usrfiles.com/ugd/5438e3_1804e3cf9de24b6e9f816475a99c94e9.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000056ca.bin
a9d3cd7934f0f16f4cf7b329d43a28e38c542ab8237325d95b2c655e49dee3ba
pdf-font-stream PDF embedded font (sfnt) at offset 0x56CA 5172 bytes
font_01_sfnt_off0000687d.bin
d108e6693bfcb1368c4892a1231d410362bd1310cc88d8aaf6c164b3a4a22f2d
pdf-font-stream PDF embedded font (sfnt) at offset 0x687D 10428 bytes