Malicious PDF — malware analysis report

Static analysis result for SHA-256 c38664134117f44d…

MALICIOUS

PDF

43.0 KB Created: 2020-08-07 08:52:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 97da0a2cb2658ceb82f4370ba8a136bf SHA-1: d06fc86a333ba8294427cdcd096e3d2d30ec5f74 SHA-256: c38664134117f44d0beb005c3ae41630488b03012153680a8930e22bab395e91
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. Additionally, it exhibits a PDF link farm heuristic, with numerous links hosted on cdn.shopify.com and other domains, suggesting a coordinated effort to distribute malicious content. The ML classifier also strongly flagged this PDF as malicious. The primary attack pattern involves luring users through the embedded link to a potentially malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=adarsha+hindu+hotel+free+pdf
    • http://worivog.shoepedals.com/uploads/1/3/1/3/131384281/vawevakasarew.pdf
    • http://narimu.jessiesfitclub.com/uploads/1/3/1/6/131637016/bafuj.pdf
    • http://files.ptccommunitygardens.org/uploads/1/3/1/6/131607232/jinokolu_penofaxadutub_bojow.pdf
    • http://files.gilliantorckler.com/uploads/1/3/0/8/130874629/gomenevidi-kinepowa-xasokipa-xupuzateseroji.pdf
    • http://tixuwe.multipleconstruction.com/uploads/1/3/1/8/131856772/zaket.pdf
    • https://cdn.shopify.com/s/files/1/0430/3391/9645/files/nomevusereluvuv.pdf
    • https://cdn.shopify.com/s/files/1/0431/1118/6588/files/58742277504.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/gubiwunezekubukezo.pdf
    • https://cdn.shopify.com/s/files/1/0433/3345/1944/files/bofaxukaxixifipov.pdf
    • https://cdn.shopify.com/s/files/1/0440/0765/3526/files/5204855178.pdf
    • https://cdn.shopify.com/s/files/1/0431/7147/9709/files/24464018394.pdf
    • https://cdn.shopify.com/s/files/1/0430/4257/0401/files/86420504894.pdf
    • https://cdn.shopify.com/s/files/1/0440/7640/0792/files/xixubu.pdf
    • https://cdn.shopify.com/s/files/1/0430/0842/6147/files/blood_type_o_diet_plan.pdf
    • https://cdn.shopify.com/s/files/1/0433/9014/0581/files/jirevufuvegedatelokajaxi.pdf
    • https://cdn.shopify.com/s/files/1/0428/2603/9463/files/77216990132.pdf
    • https://cdn.shopify.com/s/files/1/0437/2961/7057/files/mafere.pdf
    • https://cdn.shopify.com/s/files/1/0433/7270/7990/files/xapasiduwano.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005608.bin
ab6c9bf2e029bca113469e5d7bfd88965aecc3d08aee899ca554b643e290f76b
pdf-font-stream PDF embedded font (sfnt) at offset 0x5608 5120 bytes
font_01_sfnt_off00006769.bin
14c9e938e6a4e1ad6ce08968cb8038733c9243848bd38421ea5833f8da451a96
pdf-font-stream PDF embedded font (sfnt) at offset 0x6769 6508 bytes
font_02_sfnt_off00007c41.bin
6460a61b35dae3aac1689aa75a3a159288e64280229145ae1ea45ac2ff6be460
pdf-font-stream PDF embedded font (sfnt) at offset 0x7C41 10240 bytes