Malicious PDF — malware analysis report

Static analysis result for SHA-256 d75588f1eee03f64…

MALICIOUS

PDF

41.8 KB Created: 2020-08-14 13:04:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 385f63af08ee4b6b657e78ddf06bd84e SHA-1: 47d8c1c37edd6c3d3f08f4429b05784a4cbe7fa2 SHA-256: d75588f1eee03f64c22048a6fe600591cb92036919d0f46d39e0027361febb33
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains embedded links that point to a known malicious redirector, ttraff.com, which is likely intended to lure users into downloading malware. The document body, though heavily obfuscated, contains text referencing 'collage maker apkpure' and the malicious URL, reinforcing the phishing pretext. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=collage+maker++apkpure
    • http://sukokegag.cowlitzcountycjac.com/uploads/1/3/2/6/132695492/9913820.pdf
    • http://betiboz.wovenbygraceboutique.com/uploads/1/3/2/6/132682883/megelar-nofilagol.pdf
    • http://files.grandcelticpipeband.com/uploads/1/3/1/3/131379181/167166.pdf
    • http://files.littleheartrocks.com/uploads/1/3/0/8/130814124/111038.pdf
    • https://cdn.shopify.com/s/files/1/0440/2341/4942/files/5762460258.pdf
    • https://cdn.shopify.com/s/files/1/0434/4276/5976/files/movukibalibexepiminixaj.pdf
    • https://cdn.shopify.com/s/files/1/0435/9513/7187/files/psychology_openstax.pdf
    • https://cdn.shopify.com/s/files/1/0434/7317/4680/files/52488486002.pdf
    • https://cdn.shopify.com/s/files/1/0431/5106/5243/files/jagezavetigusulutufuboz.pdf
    • https://cdn.shopify.com/s/files/1/0429/2725/9811/files/mezasurewofuvuxiro.pdf
    • https://cdn.shopify.com/s/files/1/0435/2668/4824/files/97428561945.pdf
    • https://cdn.shopify.com/s/files/1/0435/5670/0319/files/48226649218.pdf
    • https://cdn.shopify.com/s/files/1/0447/8962/9079/files/download_novel_arifureta_shokugyou_de_sekai_saikyou_bahasa_indonesia.pdf
    • https://cdn.shopify.com/s/files/1/0433/8545/4757/files/94605800347.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000475c.bin
86db3e38fb90e1e70f81a4b725a7123eb509a55c8287bec5b6a2b0197790c467
pdf-font-stream PDF embedded font (sfnt) at offset 0x475C 4932 bytes
font_01_sfnt_off0000580d.bin
8243a2978354b99ad9fc1765d3878328d49e2998d0a5549394a0bdfef85e0506
pdf-font-stream PDF embedded font (sfnt) at offset 0x580D 2188 bytes
font_02_sfnt_off0000622c.bin
d1a29c12564d8f487a89a85c1766bd94860c45e097d0e737cf6d065a11c48fc3
pdf-font-stream PDF embedded font (sfnt) at offset 0x622C 10148 bytes
font_03_sfnt_off00008514.bin
39b2f4b99ee08965fd4836f89f628a00cde8346cb181131bba0308e80db8fb67
pdf-font-stream PDF embedded font (sfnt) at offset 0x8514 16092 bytes