Malicious PDF — malware analysis report

Static analysis result for SHA-256 019abc8a1668e45a…

MALICIOUS

PDF

54.6 KB Created: 2020-08-30 13:41:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2deef16464f608b9aba929f212caf127 SHA-1: 90ee5fc4ecd6a6782bd5ca7e558dad81b76dc169 SHA-256: 019abc8a1668e45af858d4acd5d57601788d9b6f515ce0ed9981b4a2acb8c6c3
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains numerous embedded links, with one specifically pointing to a known malicious redirector at 'ttraff.ru'. The document body, though heavily obfuscated, appears to be a lure related to educational worksheets, likely intended to disguise the malicious intent. The ML classifier strongly flagged this PDF as malicious, supporting the conclusion that it's designed to redirect users to harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=adding+and+subtracting+like+fractions+word+problems+worksheets
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://static.usrfiles.com/ugd/b8c837_e1883669ff4c45148f125acd4cf4194b.pdf
    • https://static.usrfiles.com/ugd/0c268c_9ea6696d556b4ac29976867bc244c0c6.pdf
    • https://static.usrfiles.com/ugd/93c935_8877e91205444ad4b2f81934dcdef747.pdf
    • https://static.usrfiles.com/ugd/b8c837_70e854ce6a3d4db89aedaaf136a267a3.pdf
    • https://cdn.shopify.com/s/files/1/0434/6681/7689/files/22662717832.pdf
    • https://static.usrfiles.com/ugd/e2b09b_4d218ca78ef34cedafbe41f83d5898c3.pdf
    • https://static.usrfiles.com/ugd/4b7290_1c64d9f964db4346967afe8b8f42a879.pdf
    • https://static.usrfiles.com/ugd/0779a3_be488050f51447d283ad391c5a83f1ac.pdf
    • https://static.usrfiles.com/ugd/913720_e20474f3ddeb4cdab34b54f58ce11e04.pdf
    • https://cdn.shopify.com/s/files/1/0439/8999/1582/files/dixieland_jazz_trumpet_sheet_music.pdf
    • https://cdn.shopify.com/s/files/1/0431/4356/1376/files/wibofa.pdf
    • https://cdn.shopify.com/s/files/1/0435/3127/2351/files/20360368785.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000082a3.bin
b1272eea0e192e2d9718ddb9cab08b5fa0df759498be1f94e7a3a123a14c7339
pdf-font-stream PDF embedded font (sfnt) at offset 0x82A3 5856 bytes
font_01_sfnt_off0000966d.bin
e59cef23b00893cdd9f5955d7cb355579ae29f1884742c6ae40daea9306ca170
pdf-font-stream PDF embedded font (sfnt) at offset 0x966D 9712 bytes
font_02_sfnt_off0000b7ef.bin
586fd2d47d7ef655ac8fcedaf3a17ac43b55ee34544d24df6525aba8b365c669
pdf-font-stream PDF embedded font (sfnt) at offset 0xB7EF 16116 bytes