Malicious PDF — malware analysis report

Static analysis result for SHA-256 259909ee9d38225a…

MALICIOUS

PDF

41.5 KB Created: 2020-08-30 18:43:42 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: af678ab711ff37914f43514e7aa10cd4 SHA-1: 561b3a28651c0a9a1d508b39cc2e9e07ececd033 SHA-256: 259909ee9d38225a793a6be277734e398f7d6bc8c84b94e00de9d66eb20969a1
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to ttraff.com. This indicates the document's primary purpose is to redirect users to potentially harmful websites. Additionally, the PDF exhibits characteristics of a link farm, with numerous embedded links, further supporting the redirection attack pattern. No scripts were extracted, but the presence of a malicious URL is sufficient evidence for this assessment.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=flysim+n%25C3%25BAmero+de+serial+de+pesca+de
    • https://static.usrfiles.com/ugd/7598fa_0d797b91341c47158039bd26cc9592ee.pdf
    • https://static.usrfiles.com/ugd/b8c837_bc5f17f1c9a64ac3bf44c0439541038a.pdf
    • https://static.usrfiles.com/ugd/b8c837_1d5a2dd33e8f4870ade6ce14afcca3b6.pdf
    • https://static.usrfiles.com/ugd/b8c837_98a7132ed7234b72bab264bd7715e189.pdf
    • https://static.usrfiles.com/ugd/7baf93_e45c17b010e0461eb7ff06d2dd78ad6c.pdf
    • https://static.usrfiles.com/ugd/b8c837_e26fdb7c845846f9941cd61456e8736b.pdf
    • https://static.usrfiles.com/ugd/906e9f_42f44b9cf29f40c1a5799e152df0b65e.pdf
    • https://static.usrfiles.com/ugd/7d1dc9_0d6dda593988433c88279e4251eec85f.pdf
    • https://static.usrfiles.com/ugd/b8c837_278e3a57eae84c0eab8999e0be6f1c5e.pdf
    • https://static.usrfiles.com/ugd/7baf93_e67b0123e0b04820b56e6f5039c373bd.pdf
    • https://static.usrfiles.com/ugd/b8c837_a905ced1868b4c9397f96f1750eac592.pdf
    • https://static.usrfiles.com/ugd/097bd5_c717888a62e34c7aa8c1ea61ebd3d207.pdf
    • https://static.usrfiles.com/ugd/7ff653_f48ce86f3d574332b9db6dbb364d15d5.pdf
    • https://static.usrfiles.com/ugd/b8c837_bb14eaa8021b4ea0883159d0c61abaf0.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000612f.bin
46346b3b248ff08a58b2adc3f314d7515bce50cc1382b96ca4dafc86b237c1f7
pdf-font-stream PDF embedded font (sfnt) at offset 0x612F 5392 bytes
font_01_sfnt_off0000733d.bin
7314146118e0ec2373f955b2a126f81cbb2eaaa8b092cfb7f5f0705288f4322e
pdf-font-stream PDF embedded font (sfnt) at offset 0x733D 11044 bytes