Malicious PDF — malware analysis report

Static analysis result for SHA-256 c6bb52c4be44e89b…

MALICIOUS

PDF

40.6 KB Created: 2020-09-05 12:49:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b11d453037869f7aa45f733c8e107634 SHA-1: b52336dd9a6bb050dea362c06c7fb74a66be534d SHA-256: c6bb52c4be44e89bca4856342b95813c4a7bebe5500916021936a347b8a1b587
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.club/wix?keyword=abrahaminte+santhathikal+bgm+music'. This URL is presented within the document body, suggesting a phishing or social engineering lure. The PDF also contains a large number of external links, many hosted on Shopify, indicating a link farm designed to obscure the malicious destination. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=abrahaminte+santhathikal+bgm+music
    • https://cdn.shopify.com/s/files/1/0433/1087/4777/files/saxapixotetalot.pdf
    • https://cdn.shopify.com/s/files/1/0430/1642/1529/files/humidity_and_temperature_sensor_rht03_datasheet.pdf
    • https://cdn.shopify.com/s/files/1/0434/4525/6352/files/56815023478.pdf
    • https://cdn.shopify.com/s/files/1/0431/4287/3249/files/61654157534.pdf
    • https://static.usrfiles.com/ugd/599f1c_58750b69b10f417f8ab42a81413be43b.pdf
    • https://static.usrfiles.com/ugd/b8c837_6cc8e483236b4629a2d83a1a97a25f86.pdf
    • https://static.usrfiles.com/ugd/c4ccc4_7dc484b6ca1949b495fdb05ef132585b.pdf
    • https://cdn.shopify.com/s/files/1/0432/2879/0946/files/50658948626.pdf
    • https://cdn.shopify.com/s/files/1/0460/2416/3487/files/berea_technical_college_application_form_2019.pdf
    • https://cdn.shopify.com/s/files/1/0430/6858/8194/files/55715294435.pdf
    • https://cdn.shopify.com/s/files/1/0431/3471/4017/files/sokubesas.pdf
    • https://cdn.shopify.com/s/files/1/0430/6305/0394/files/oxford_dictionary_online.pdf
    • https://cdn.shopify.com/s/files/1/0433/5733/9803/files/apprendre_l_espagnol.pdf
    • https://cdn.shopify.com/s/files/1/0428/4622/4551/files/velokozerakebaludepen.pdf
    • https://cdn.shopify.com/s/files/1/0438/1645/2258/files/s._y._b._com_books_mumbai_university.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004b5b.bin
65792052e06b8330dd7ff2352079c0ef411f63428fc4c1278d5e0ba07872aa92
pdf-font-stream PDF embedded font (sfnt) at offset 0x4B5B 5180 bytes
font_01_sfnt_off00005cc9.bin
a95184bc1478db416fa70bec34301ecf91e917a070dd86f309139a3f16788526
pdf-font-stream PDF embedded font (sfnt) at offset 0x5CC9 13788 bytes
font_02_sfnt_off0000878b.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0x878B 4324 bytes