Malicious PDF — malware analysis report

Static analysis result for SHA-256 5a0b31299b5f4413…

MALICIOUS

PDF

42.5 KB Created: 2020-08-29 13:40:41 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c6a7393f0a66483176bcc9845157f86e SHA-1: a6108c850bb961e685d3a00ff0fb5cb0ba4008c5 SHA-256: 5a0b31299b5f4413f002328aab339b27ea5b7a9712f3e788ebdcf8907fdd32df
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a malicious redirector link disguised as a search query. The document body, though heavily obfuscated, contains references to the topic 'Difference between cat5 and cat6' and includes numerous links to external PDFs, many hosted on Shopify and static.usrfiles.com. The primary malicious URL is https://ttraff.ru/wix?keyword=difference+between+cat5+and+cat6, which is flagged as a known malicious redirector.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=difference+between+cat5+and+cat6
    • https://cdn.shopify.com/s/files/1/0432/9770/2046/files/89879196881.pdf
    • https://cdn.shopify.com/s/files/1/0435/6174/6595/files/turn_off_automatic_sign_in_gmail_android.pdf
    • https://cdn.shopify.com/s/files/1/0427/6980/9564/files/in_search_of_the_myreque_quick_guide.pdf
    • https://cdn.shopify.com/s/files/1/0428/5746/3971/files/sekas.pdf
    • https://cdn.shopify.com/s/files/1/0428/8148/2919/files/sajesafok.pdf
    • https://cdn.shopify.com/s/files/1/0446/0825/8211/files/southwest_airlines_2020_case_study.pdf
    • https://cdn.shopify.com/s/files/1/0437/2480/0168/files/zowifimiresonakipes.pdf
    • https://static.usrfiles.com/ugd/b8c837_295d1b478cd3491e9d6f63357d716718.pdf
    • https://static.usrfiles.com/ugd/dd4472_5620994d9b62403aa4a4ff63a8a0525f.pdf
    • https://static.usrfiles.com/ugd/b8c837_ca74d9dd5a584ad8b942c1ef8aaa3821.pdf
    • https://static.usrfiles.com/ugd/b8c837_d25d82c8fd9f4ffeb8bf7ae5e9b12481.pdf
    • https://static.usrfiles.com/ugd/b8c837_955a13aea1074fa1b367fd6c49cbe768.pdf
    • https://static.usrfiles.com/ugd/b8c837_afe59185dfcb4e8d95f30066b694701f.pdf
    • https://static.usrfiles.com/ugd/33c377_bf0ea49d4576444f8bb4b2e463b4fee2.pdf
    • https://static.usrfiles.com/ugd/b8c837_3a4ea0cd60014030b103700e0c3e7d7e.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000066f0.bin
19d80bc54c0346221dfb2716e7148caa23ff45e79af91b46d2666c6e596285b8
pdf-font-stream PDF embedded font (sfnt) at offset 0x66F0 5312 bytes
font_01_sfnt_off00007923.bin
3aa5843d04aec67f625e3ed859d61f34c382ca784c1791e5f4796bf499dcac4a
pdf-font-stream PDF embedded font (sfnt) at offset 0x7923 10528 bytes