Malicious PDF — malware analysis report

Static analysis result for SHA-256 0e459eeb383cff57…

MALICIOUS

PDF

47.1 KB Created: 2020-07-28 15:21:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0619b62ea3d2b602355f6315083c97f3 SHA-1: 515914655900ee17ee5922358de642881dcabe67 SHA-256: 0e459eeb383cff5783ca6787cded492d4bf8bebf0232bba189efe058db23dbec
174 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript T1203 Exploitation for Client Execution

The PDF contains a malicious redirector link pointing to 'ttraff.cc', which is flagged as malicious. It also hosts a large number of external PDF links, suggesting a link farm or redirection scheme. The document body, though heavily obfuscated, contains text related to 'Delaware secretary of state annual report fee', aligning with the callback phishing lure heuristic.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=delaware+secretary+of+state+annual+report+fee
    • http://files.plymouthalliance.org/uploads/1/3/1/4/131437249/d9c12fa3b.pdf
    • http://files.cabbagetreecreek.org/uploads/1/3/0/9/130969297/wasebajetaja.pdf
    • http://files.andrewsomera.com/uploads/1/3/1/3/131380730/gofamila.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0437/1247/9382/files/10684489584.pdf
    • https://cdn.shopify.com/s/files/1/0437/6385/9610/files/96777022937.pdf
    • https://cdn.shopify.com/s/files/1/0432/3934/2247/files/mifozose.pdf
    • https://cdn.shopify.com/s/files/1/0434/2503/8497/files/52309325471.pdf
    • https://cdn.shopify.com/s/files/1/0431/2596/4957/files/28509913743.pdf
    • https://cdn.shopify.com/s/files/1/0429/8434/1657/files/97611407242.pdf
    • https://cdn.shopify.com/s/files/1/0429/9125/5713/files/99002173778.pdf
    • https://cdn.shopify.com/s/files/1/0433/0982/6213/files/selibisefireso.pdf
    • https://cdn.shopify.com/s/files/1/0435/8491/3563/files/fanavitarakasomanafeja.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000077ef.bin
dfbc9776387982c17201f2cc60be5d58adf6842ce860f2a42be032c352a07096
pdf-font-stream PDF embedded font (sfnt) at offset 0x77EF 5036 bytes
font_01_sfnt_off00008939.bin
c7b747d1c1518413327120a2c1cc2311ceb4981209dac57a2ef0054397dbdc18
pdf-font-stream PDF embedded font (sfnt) at offset 0x8939 10916 bytes