Malicious PDF — malware analysis report

Static analysis result for SHA-256 596f4f93d7bf2ba8…

MALICIOUS

PDF

274.8 KB Created: 2020-08-04 13:33:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cf02390abffa6938261560bf232f830d SHA-1: f5dcf180b0eb0eae91bf231875399bc56c5a355f SHA-256: 596f4f93d7bf2ba8c58981a2d418181193d2f78448b923f27b8d4d3537feed2c
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. The document body, though heavily obfuscated, appears to contain the same URL. This strongly suggests the document's primary purpose is to lure the user to this malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=aqeedah+al+wasitiyyah+arabic+pdf
    • http://files.teaching.yfolajimi.com/uploads/1/3/2/6/132696325/zeniburaninedem-lewup.pdf
    • http://rasefaxat.irokoandfeather.com/uploads/1/3/2/6/132695278/802175.pdf
    • http://files.simplifiedcomm.com/uploads/1/3/1/4/131437680/9977842.pdf
    • https://cdn.shopify.com/s/files/1/0440/7335/3366/files/sinubupiteneg.pdf
    • https://cdn.shopify.com/s/files/1/0427/9474/6023/files/merobuguregi.pdf
    • https://cdn.shopify.com/s/files/1/0431/5850/3584/files/81983774678.pdf
    • https://cdn.shopify.com/s/files/1/0431/2875/0241/files/puriterurudibigupedam.pdf
    • https://cdn.shopify.com/s/files/1/0432/5248/2208/files/misudoveparigidufovibefam.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/15138334831.pdf
    • https://cdn.shopify.com/s/files/1/0439/1239/6968/files/74609732222.pdf
    • https://cdn.shopify.com/s/files/1/0431/3330/4981/files/xozewusagigazuj.pdf
    • https://cdn.shopify.com/s/files/1/0439/8238/9406/files/68826568392.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/zofes.pdf
    • https://cdn.shopify.com/s/files/1/0429/9476/1877/files/57859178844.pdf
    • https://cdn.shopify.com/s/files/1/0429/5032/8486/files/zafifej.pdf
    • https://cdn.shopify.com/s/files/1/0428/1804/4070/files/togokubijono.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_007_off000400ad.bin
44c47178f2aaf4c3e90d77ac0edfa4a3b83a9c1cbc06f4918e36bae638b11363
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x400AD 35896 bytes
font_00_sfnt_off0003c67e.bin
064072e6df62b3da730f13877b05c7173230bbcbbf12f277edaf468a48cc2821
pdf-font-stream PDF embedded font (sfnt) at offset 0x3C67E 5692 bytes
font_01_sfnt_off0003d9ea.bin
08ea4949772b28fd81e7c70e137d4b928a8bf84eb5aa6c22100cace377ae9684
pdf-font-stream PDF embedded font (sfnt) at offset 0x3D9EA 12452 bytes