Malicious PDF — malware analysis report

Static analysis result for SHA-256 37a31a7b5d412be0…

MALICIOUS

PDF

43.6 KB Created: 2020-08-13 09:39:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0ffe03f465dc69406c2b63ecba4405c6 SHA-1: 7fca3dcd1867b78a0245bb1258171152efa7ba8b SHA-256: 37a31a7b5d412be0547fc1689f0fefe6c4eb4af8279ef572caa3d47a16d5d564
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was flagged by a machine learning classifier and heuristics indicate it contains a malicious redirector link and a large number of external PDF links, suggesting a link farm or redirection strategy. The primary malicious URL identified is ttraff.ru, which is likely used to direct users to further malicious content. The document body itself is largely unreadable due to encoding issues but contains references to the URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wb?keyword=hukum%20perlindungan%20konsumen%20pdf
    • http://files.murderfoot.com/uploads/1/3/1/0/131070529/6daf2f39ecfd.pdf
    • http://babaxunod.ingridliberte.com/uploads/1/3/1/4/131437619/c90a47aae512cd.pdf
    • http://files.coldchocolatemusic.com/uploads/1/3/0/7/130740051/bamugogexavozi_nerewajasu_kegedukane_wawajofazekega.pdf
    • https://cdn.shopify.com/s/files/1/0435/0921/9492/files/icao_annex_14_heliports.pdf
    • https://cdn.shopify.com/s/files/1/0432/6889/8966/files/45395340058.pdf
    • https://cdn.shopify.com/s/files/1/0431/1741/2501/files/roxitupegit.pdf
    • https://cdn.shopify.com/s/files/1/0433/0710/6462/files/fuwikevazezur.pdf
    • https://cdn.shopify.com/s/files/1/0438/6045/9685/files/familia_y_embarazo_adolescente.pdf
    • https://cdn.shopify.com/s/files/1/0429/0913/9110/files/jisosofexuteparefujojew.pdf
    • https://cdn.shopify.com/s/files/1/0429/7372/4825/files/likiwewobasotefu.pdf
    • https://cdn.shopify.com/s/files/1/0429/5049/2316/files/30665052693.pdf
    • https://cdn.shopify.com/s/files/1/0438/2552/8989/files/lehninger_biochemistry_book.pdf
    • https://cdn.shopify.com/s/files/1/0434/1750/1853/files/guia_ceneval_2020.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006e9e.bin
33939c6d5ac4c70dbfe6ac8933f5359dfb1c5159813923555f27d6ce83a9c13d
pdf-font-stream PDF embedded font (sfnt) at offset 0x6E9E 5388 bytes
font_01_sfnt_off000080d2.bin
f6f7f161526f68c0816fd529e4038e190879be855846b7fab2cfb7b71f68595e
pdf-font-stream PDF embedded font (sfnt) at offset 0x80D2 9732 bytes