Malicious PDF — malware analysis report

Static analysis result for SHA-256 bbd7cdb6a083ed21…

MALICIOUS

PDF

51.5 KB Created: 2020-09-02 20:04:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9a2fd58cc279bbeb7e70a6a1ca0dce39 SHA-1: 65266cf838ec8558520effb50a37125b432e3d1c SHA-256: bbd7cdb6a083ed21741bdd47c27f55ffa1d9296cccd9f91d46dc8046164e17c1
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://ttraff.com/pify?keyword=android+studio+sdk+location+windows'. Additionally, a PDF link farm heuristic indicates the document is designed to host numerous external links. The ML classifier also strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains the same URL, reinforcing the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=android+studio+sdk+location+windows
    • https://static.usrfiles.com/ugd/b8c837_b1ffb517261f4ccfa867406991f5cb14.pdf
    • https://static.usrfiles.com/ugd/80c1db_895f7d075467480ba94a2d9cbfbd6f59.pdf
    • https://static.usrfiles.com/ugd/a76634_1dd6dee9718441c4be2089d007725d34.pdf
    • https://static.usrfiles.com/ugd/b8c837_98fc5aa7399b4310be49e70d6ba902a8.pdf
    • https://static.usrfiles.com/ugd/6f7357_faee4f53199e41638d57e2529c0a3b0d.pdf
    • https://static.usrfiles.com/ugd/4b68be_5c0381ddc4884e46b5cf1841fd6a73bb.pdf
    • https://static.usrfiles.com/ugd/338562_7e1d171452294559b33e61f95c1bfe02.pdf
    • https://static.usrfiles.com/ugd/21a131_3b3c45fe4dd1461e92d49d29eb089971.pdf
    • https://static.usrfiles.com/ugd/724bd4_6c1dfda8b4a14abfa63d0dcfa58294b8.pdf
    • https://cdn.shopify.com/s/files/1/0431/7829/5450/files/91382029405.pdf
    • https://cdn.shopify.com/s/files/1/0431/8684/7905/files/65560236403.pdf
    • https://cdn.shopify.com/s/files/1/0431/2412/9952/files/mother_3_fan_translation_rom.pdf
    • https://cdn.shopify.com/s/files/1/0432/6604/8165/files/fagadafide.pdf
    • https://cdn.shopify.com/s/files/1/0434/9945/4629/files/45394180249.pdf
    • https://static.usrfiles.com/ugd/f96b02_9f507d95519c4acb81b680e3d5d1162d.pdf
    • https://static.usrfiles.com/ugd/b8c837_257ff7cb4bf341fd9cb2c9f079d40954.pdf
    • https://static.usrfiles.com/ugd/7e6083_5230115ede3e4d3f9a227b0c0c2ee78e.pdf
    • https://static.usrfiles.com/ugd/b8c837_7af8bd65cb784c87af0e8e52cf512c72.pdf
    • https://static.usrfiles.com/ugd/a2ebd8_b6f04124c7574452a37c9ca830947989.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008adb.bin
e8e609b460bf6cef15c7a1c510842f2fbd827eb576fda4e0d86aaecb435a378f
pdf-font-stream PDF embedded font (sfnt) at offset 0x8ADB 5080 bytes
font_01_sfnt_off00009c46.bin
1d6a270f6391b8092654ab26001781ff24111bc6c442884fdfa26dbabd3a3578
pdf-font-stream PDF embedded font (sfnt) at offset 0x9C46 10560 bytes