Malicious PDF — malware analysis report

Static analysis result for SHA-256 05b3c969771c02da…

MALICIOUS

PDF

42.1 KB Created: 2020-08-30 02:38:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a45b1f4d8b5211bd6d89bca76269ee41 SHA-1: 031ea739c7804da5e337e16fd1d097197fb1e79b SHA-256: 05b3c969771c02da2340041c1ec3de9db10dc025c1dc3578bf30d7adbf0998cb
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link to a known malicious redirector, ttraff.ru, which is likely used to funnel victims to malicious content. The document body, though heavily obfuscated, contains the same URL, suggesting an attempt to disguise the malicious link as relevant content. The presence of numerous other PDF links, many pointing to Shopify domains, indicates a potential SEO link farm used for traffic generation or obfuscation.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=gunsmith+part+1+tarkov
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0430/4994/3202/files/88400724448.pdf
    • https://cdn.shopify.com/s/files/1/0433/0081/4998/files/animation_movie_creator_software_free.pdf
    • https://cdn.shopify.com/s/files/1/0435/1046/4667/files/62142618294.pdf
    • https://cdn.shopify.com/s/files/1/0440/6509/5845/files/46322348035.pdf
    • https://static.usrfiles.com/ugd/b8c837_5d787bbd8e0d44fdb1837c1c99718a4e.pdf
    • https://static.usrfiles.com/ugd/91e123_01c0569cda184c4bb7b396a68ffb8242.pdf
    • https://static.usrfiles.com/ugd/b8c837_634d425dce084fbb89144d1740260d3d.pdf
    • https://static.usrfiles.com/ugd/de65f7_bbaec988ce7e4ddd94ad6c76bcf7c4db.pdf
    • https://static.usrfiles.com/ugd/6f58fb_386fba8426b3404d9cc9a5bb470695ae.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000058aa.bin
2a69545f8a9d104697b847a0f548493cbc920d2d91a2c508c9ca03512f8941e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x58AA 6416 bytes
font_01_sfnt_off00006874.bin
16935c1975e5c12df28b25e05d62c1157800a3b9a08ad9756fe5ed6c2f807a18
pdf-font-stream PDF embedded font (sfnt) at offset 0x6874 5232 bytes
font_02_sfnt_off00007a1c.bin
4af39dbe6eac41bc127e06e43edd6ec9a5856e36003087b632b4c73cf3e6ca59
pdf-font-stream PDF embedded font (sfnt) at offset 0x7A1C 9956 bytes