Malicious PDF — malware analysis report

Static analysis result for SHA-256 14ba797c0a94b254…

MALICIOUS

PDF

65.3 KB Created: 2020-08-21 02:15:30 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 42c69c4d7db5cb995fdc6f0f78dfd9c7 SHA-1: 463029e8153cf7fcd2997ec9d9ba995d9bb523c5 SHA-256: 14ba797c0a94b254eeee09cb363f33a15bfd4f3319d22089ee699a67b4949773
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.ru'. The document body, though heavily obfuscated, also contains this URL, suggesting an attempt to lure the user to a malicious site under the guise of sheet music. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=spring+sonata+beethoven+sheet+music
    • http://wemipa.molliebing.com/uploads/1/3/2/8/132814930/gepozevaze-lipuruto-talagalefiduf.pdf
    • http://files.synbim.co.uk/uploads/1/3/1/3/131383456/9723114.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0431/2560/4513/files/nilosivilobokov.pdf
    • https://cdn.shopify.com/s/files/1/0427/4287/4278/files/devilbiss_air_power_company.pdf
    • https://cdn.shopify.com/s/files/1/0440/4012/6614/files/36549969596.pdf
    • https://cdn.shopify.com/s/files/1/0440/4323/9589/files/frisco_texas_weather_report.pdf
    • https://cdn.shopify.com/s/files/1/0434/7320/7446/files/the_gregg_reference_manual_11th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0429/9715/3943/files/fitilabuvidi.pdf
    • https://cdn.shopify.com/s/files/1/0432/8954/2809/files/diraxula.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009c01.bin
bd8bf766c1c46fff3bd10a83c4a6809610fcbb4666554abd1963e3de662721a1
pdf-font-stream PDF embedded font (sfnt) at offset 0x9C01 5620 bytes
font_01_sfnt_off0000aef6.bin
685b17b7230089303d820f2f03bf5f72d5501fe267887a1965e111471f0cd7cb
pdf-font-stream PDF embedded font (sfnt) at offset 0xAEF6 16392 bytes
font_02_sfnt_off0000e371.bin
8b5da12c2f5a7ee90c92fbc7e0259540bbefb8d268f63ec3b804f780b8926204
pdf-font-stream PDF embedded font (sfnt) at offset 0xE371 16144 bytes