Malicious PDF — malware analysis report

Static analysis result for SHA-256 d648b31dee2600ad…

MALICIOUS

PDF

59.1 KB Created: 2020-08-22 03:21:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d84490e15e2acfb751c44f7be7e5dda4 SHA-1: bf604420f8a49161f4a0f3d0b600796e08119a02 SHA-256: d648b31dee2600ad0332b04403dcada7e468cab01c9b74889e9d4c2466ccd41c
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by multiple critical heuristics for containing malicious redirector links and a large number of external links, suggesting a link farm or phishing attempt. The primary malicious URL identified is https://ttraff.com/pify?keyword=yuddha+kanda+kannada+film+songs+free, which is known to host redirector infrastructure. The document body, though heavily obfuscated, also contains this URL, reinforcing its role in the attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9948

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=yuddha+kanda+kannada+film+songs+free
    • http://files.naramatachildcare.com/uploads/1/3/0/7/130775063/2232125.pdf
    • http://kujuz.peakphotographyllc.com/uploads/1/3/1/4/131437689/xelofolelo_sikufisorigu.pdf
    • http://files.lynngoodpasture.com/uploads/1/3/1/4/131482886/gibapozotuvokuj-tisewigefev-xolapagimub-wupij.pdf
    • http://files.emeraldcityreviewer.com/uploads/1/3/0/7/130738779/5059149.pdf
    • http://vexew.spotteddots.com/uploads/1/3/1/4/131437069/3026803.pdf
    • http://kujuz.pea
    • https://cdn.shopify.com/s/files/1/0460/6561/5003/files/32308957690.pdf
    • https://cdn.shopify.com/s/files/1/0452/1938/1399/files/nemisezomutarafagetexisu.pdf
    • https://cdn.shopify.com/s/files/1/0440/6099/9830/files/benoximafutozuwamujusofap.pdf
    • https://cdn.shopify.com/s/files/1/0435/9431/7981/files/6902322603.pdf
    • https://cdn.shopify.com/s/files/1/0430/7537/1159/files/budgeting_and_profit_planning.pdf
    • https://cdn.shopify.com/s/files/1/0427/6905/5911/files/pivuguporutisozajowetakub.pdf
    • https://cdn.shopify.com/s/files/1/0437/8315/9957/files/big_data_technologies_a_survey.pdf
    • https://cdn.shopify.com/s/files/1/0435/4395/3563/files/hernando_county_school_board.pdf
    • https://cdn.shopify.com/s/files/1/0431/6459/8434/files/ventricular_arrhythmias.pdf
    • https://cdn.shopify.com/s/files/1/0428/5199/1719/files/bkav_pro_full_crack_2016.pdf
    • https://cdn.shopify.com/s/files/1/0437/5488/1175/files/87853600085.pdf
    • https://cdn.shopify.com/s/files/1/0435/7272/3875/files/jivajefaturilomoluzifigun.pdf
    • https://cdn.shopify.com/s/files/1/0434/2143/4005/files/impact_of_internet_on_students_academic_performance_questionnaire.pdf
    • https://cdn.shopify.com/s/files/1/0435/7029/9038/files/14380648435.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a6e5.bin
82b68e6d68e5c6b88ffdd9963eea364bdd059f4da2bdcb01d6226394743d31e7
pdf-font-stream PDF embedded font (sfnt) at offset 0xA6E5 5348 bytes
font_01_sfnt_off0000b8df.bin
30cf7580cdcc3095aed790c4e10f9eda4e85bd88fb99a653e1288d200f646a2e
pdf-font-stream PDF embedded font (sfnt) at offset 0xB8DF 15192 bytes