Malicious PDF — malware analysis report

Static analysis result for SHA-256 bda172acddc9a34f…

MALICIOUS

PDF

44.1 KB Created: 2020-09-05 09:44:28 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b20bbd2c384a36e45aaf654fa766cf5e SHA-1: dcc5646c4b696980480939cd0399e42bf6b3f681 SHA-256: bda172acddc9a34f44938fbb138bbb5412b150387215401dc58ec7e10d972024
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a malicious redirector link, identified by the critical PDF_MALICIOUS_REDIRECTOR_LINK heuristic. It also features a large number of external links, as indicated by PDF_SEO_LINK_FARM. The primary malicious URL is https://ttraff.me/wix?keyword=emulator+android+sur+ios+11, which likely serves as a gateway to further malicious content or phishing pages. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=emulator+android+sur+ios+11
    • https://cdn.shopify.com/s/files/1/0431/2930/7293/files/cinematography_theory_and_practice_3rd_edition.pdf
    • https://cdn.shopify.com/s/files/1/0439/2747/0235/files/12537505357.pdf
    • https://cdn.shopify.com/s/files/1/0431/6289/4495/files/42839999215.pdf
    • https://static.usrfiles.com/ugd/02ccf7_017d6700547b4e87a4eab96f2f775e81.pdf
    • https://static.usrfiles.com/ugd/b8c837_8e1aa1f06bcf4ed6b8c94da83f48776a.pdf
    • https://cdn.shopify.com/s/files/1/0427/7311/9143/files/16599464565.pdf
    • https://cdn.shopify.com/s/files/1/0429/0176/6310/files/allen_carr_easy_way_to_lose_weight_free_download.pdf
    • https://static.usrfiles.com/ugd/64f9d2_30e5e9c2f629457b995270880097b0a6.pdf
    • https://static.usrfiles.com/ugd/b4609a_bc9fe5d4373b4f529ec5024750b611cb.pdf
    • https://static.usrfiles.com/ugd/0251f0_cc7cb66898d94345afb1746dc5a23392.pdf
    • https://static.usrfiles.com/ugd/0af078_52a7faaf6599400784e7010dfd5e9c71.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007134.bin
9006df7ee9136c9bacdc2f6934041920ea1fcf9f0dbc63f37e7dffc3706b9895
pdf-font-stream PDF embedded font (sfnt) at offset 0x7134 4980 bytes
font_01_sfnt_off0000820a.bin
c9335afa0121874281dc4c7b0ac72b1c98900119ccff7182b7b1e65627f891e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x820A 10000 bytes