Malicious PDF — malware analysis report

Static analysis result for SHA-256 29762bed8a61c48e…

MALICIOUS

PDF

57.5 KB Created: 2020-08-30 16:58:12 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3661c6e25400ad709b63c21081f7e838 SHA-1: bad06fec400992fc0a9712160579dbd87e8f01da SHA-256: 29762bed8a61c48e3d81ab35c2246765d694ae56452c80588aebe2a2b29f8b19
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.ru'. Additionally, it exhibits a PDF link farm heuristic, suggesting an attempt to distribute or mask malicious links. The ML classifier also strongly flagged this PDF as malicious. The document body, though partially corrupted, contains the same suspicious URL, reinforcing its role as the primary lure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=ravi+belagere+books+pdf
    • https://cdn.shopify.com/s/files/1/0445/3515/2804/files/samsung_led_tv_manual.pdf
    • https://cdn.shopify.com/s/files/1/0432/5372/7387/files/dbt_distress_tolerance_worksheets.pdf
    • https://cdn.shopify.com/s/files/1/0437/1978/6645/files/rorijovugovurafuw.pdf
    • https://cdn.shopify.com/s/files/1/0428/4612/6247/files/como_converter_um_arquivo_para_autocad.pdf
    • https://static.usrfiles.com/ugd/b8c837_a4cd63a0844e4169966e7bb9795fa5f2.pdf
    • https://static.usrfiles.com/ugd/3f0e57_93256e20344145ec9e60cbc7e264b196.pdf
    • https://cdn.shopify.com/s/files/1/0434/8801/8598/files/avengers_infinity_war_2_trailer_free.pdf
    • https://cdn.shopify.com/s/files/1/0432/5274/4356/files/zubofedowavopetiwabesa.pdf
    • https://cdn.shopify.com/s/files/1/0430/0357/6481/files/mogodipalefumexiteza.pdf
    • https://cdn.shopify.com/s/files/1/0428/8688/9639/files/23520106854.pdf
    • https://cdn.shopify.com/s/files/1/0431/1325/0972/files/32870549425.pdf
    • https://cdn.shopify.com/s/files/1/0462/6622/0695/files/zener_breakdown_and_avalanche_breakdown.pdf
    • https://cdn.shopify.com/s/files/1/0431/1715/0368/files/11831928182.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/97253363073.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00006982.bin
2a8b0ad0028bf1173d0c043db391c7b276cd0008760825815349536091dcd94b
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6982 23180 bytes
font_00_sfnt_off000056cc.bin
d48e85a09c5530bff3d804b821cf51fc260a83e2ff703c94a72f396ed96f8297
pdf-font-stream PDF embedded font (sfnt) at offset 0x56CC 5480 bytes
font_02_sfnt_off0000969a.bin
b48365bc70239bc6d73eeb035861c99d7eaaa7a7193da2e759f71ff2db3f9af1
pdf-font-stream PDF embedded font (sfnt) at offset 0x969A 13700 bytes
font_03_sfnt_off0000c1d9.bin
ead7fd593d7f5feef6f283420e9b55f8fa4552f107c64b0063d474dd3355abd8
pdf-font-stream PDF embedded font (sfnt) at offset 0xC1D9 16164 bytes