Malicious PDF — malware analysis report

Static analysis result for SHA-256 118d1711230c7bea…

MALICIOUS

PDF

427.7 KB Created: 2020-08-31 13:01:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4a0b4d4f5b7656707d2ae16596495d58 SHA-1: 59907664b32f7c75851f1e2c2638be433c44eea0 SHA-256: 118d1711230c7beabee02aabc8cfd28c402157cf22d47cd3cefd30a3e47d2478
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a malicious redirector link disguised as an offer for free online content. The ML classifier and the critical heuristic firing confirm the malicious nature of the link, which points to the domain 'ttraff.club'. This domain is likely used to redirect users to further malicious sites or download unwanted content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9883

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=read+percy+jackson+online+free
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://static.usrfiles.com/ugd/b8c837_c6eba044e763446e97e044e59ea99c06.pdf
    • https://static.usrfiles.com/ugd/576447_553512858db34218a8017586ba8e35ab.pdf
    • https://static.usrfiles.com/ugd/b8c837_ec8c941a7d414054beb542e1639821aa.pdf
    • https://static.usrfiles.com/ugd/b8c837_4622dc215d2e4f94b6f89ab7e5d0f771.pdf
    • https://static.usrfiles.com/ugd/384ea4_fc288fc74a3648f8b7d89e5267431598.pdf
    • https://static.usrfiles.com/ugd/b8c837_b773e220c0374784937e1a949d98038a.pdf
    • https://cdn.shopify.com/s/files/1/0434/3637/6231/files/kidetogaxewu.pdf
    • https://cdn.shopify.com/s/files/1/0428/3963/8179/files/31348390125.pdf
    • https://cdn.shopify.com/s/files/1/0429/9682/6261/files/21021841180.pdf
    • https://cdn.shopify.com/s/files/1/0437/0425/4615/files/96021758394.pdf
    • https://cdn.shopify.com/s/files/1/0434/6164/0358/files/find_the_slope_of_each_line_worksheet_answers.pdf
    • https://cdn.shopify.com/s/files/1/0429/0835/2679/files/guzotozitimerawanovu.pdf
    • https://cdn.shopify.com/s/files/1/0431/5129/4619/files/vojorudoduwedizomowawid.pdf
    • https://cdn.shopify.com/s/files/1/0434/2887/2359/files/andy_cutler_chelation.pdf
    • https://cdn.shopify.com/s/files/1/0433/9941/3925/files/23722073168.pdf
    • https://cdn.shopify.com/s/files/1/0428/2620/3302/files/benzoylformic_acid_molar_mass.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00066604.bin
f003eb7ebbdb03c281962974e874ccf9c10e7296e6871f9af46f519f25607695
pdf-font-stream PDF embedded font (sfnt) at offset 0x66604 5396 bytes
font_01_sfnt_off00067889.bin
726caf1f0073f19f14fffe644da2eba794deaf0402095a8a2b641d2bd099eff8
pdf-font-stream PDF embedded font (sfnt) at offset 0x67889 11500 bytes