Malicious PDF — malware analysis report

Static analysis result for SHA-256 32b17a98fa5f1edc…

MALICIOUS

PDF

293.7 KB Created: 2020-08-30 22:55:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c57d44fa2c257bd03aeefd4147cea8cf SHA-1: c2703261c37ec6e45263483be5abcc693f0e2cd9 SHA-256: 32b17a98fa5f1edcfa42003a799123b518f2fdfb7ea6e3c324bccf5344451ae7
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a link to a known malicious redirector, https://ttraff.ru/wix?keyword=callioli+algebra+linear+pdf. This indicates an attempt to lure the user to a malicious site, likely for further exploitation or credential harvesting. The ML classifier also flagged this PDF with high confidence. No scripts were extracted, and the document body was heavily obfuscated.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=callioli+algebra+linear+pdf
    • https://cdn.shopify.com/s/files/1/0433/0507/4838/files/juzotiro.pdf
    • https://cdn.shopify.com/s/files/1/0429/3623/8236/files/mosogigefunu.pdf
    • https://cdn.shopify.com/s/files/1/0436/3350/8512/files/imperio_bizantino_historia.pdf
    • https://static.usrfiles.com/ugd/a18aa6_489a80b78a884665960a68dc1fca3bd9.pdf
    • https://static.usrfiles.com/ugd/b8c837_3cefc7238c4540a884b66f684e1a503d.pdf
    • https://static.usrfiles.com/ugd/b8c837_e3625d85e0564200a1a4d28d1576a5a4.pdf
    • https://cdn.shopify.com/s/files/1/0429/1310/4028/files/35620783602.pdf
    • https://cdn.shopify.com/s/files/1/0431/0971/2021/files/29422554879.pdf
    • https://cdn.shopify.com/s/files/1/0464/5286/7240/files/coliform_bacteria_urinary_tract_infections.pdf
    • https://cdn.shopify.com/s/files/1/0463/7599/3505/files/malutujewigazinunazulux.pdf
    • https://cdn.shopify.com/s/files/1/0431/7977/0019/files/xaxejakaluwaji.pdf
    • https://cdn.shopify.com/s/files/1/0429/9050/2042/files/brain_teasers_puzzles_with_answers.pdf
    • https://cdn.shopify.com/s/files/1/0440/6408/0024/files/al_quran_madinah_terjemahan.pdf
    • https://cdn.shopify.com/s/files/1/0432/0247/8237/files/promissory_note_payable_on_demand_template.pdf
    • https://cdn.shopify.com/s/files/1/0430/8526/7097/files/37053421605.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00042748.bin
5c05cfd6ddc942ff82a640054d8a1734d8e0940a1cda55e7bb48a8dfdf3c96ee
pdf-font-stream PDF embedded font (sfnt) at offset 0x42748 5076 bytes
font_01_sfnt_off0004388d.bin
643e632164878d56f31a62f10d0c636d7c6bdd594c656f179e871eb3980f025e
pdf-font-stream PDF embedded font (sfnt) at offset 0x4388D 20320 bytes
font_02_sfnt_off0004735c.bin
9dd3e911c180e4b73a62bd0f4ab6aed3b27f5a5a765fbf3cb36ae54e7f643b9b
pdf-font-stream PDF embedded font (sfnt) at offset 0x4735C 16416 bytes