Malicious PDF — malware analysis report

Static analysis result for SHA-256 696050b1bd0ff502…

MALICIOUS

PDF

202.9 KB Created: 2020-08-19 23:05:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fe025274f4b94687a0e7d5561d4943b4 SHA-1: 983029f23d379df123e4e34ea8f80f3eac4d6dc3 SHA-256: 696050b1bd0ff5020ab9452922542741b04105a31313bb6a9153e152967a99a3
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://ttraff.ru/pify?keyword=adrenal+adenoma+guidelines+uk'. The document body, though heavily obfuscated, also contains this URL, suggesting it is the primary lure. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted, but the presence of a malicious URL indicates a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=adrenal+adenoma+guidelines+uk
    • http://files.energyworx2.co.uk/uploads/1/3/1/0/131070051/2657940.pdf
    • http://files.gmskiclub.org/uploads/1/3/1/0/131070207/64076d0.pdf
    • http://taxosenut.upholsteringmelbourne.com.au/uploads/1/3/2/6/132681579/4b07c0eb63e8.pdf
    • http://lumufajoz.country-charms.com/uploads/1/3/0/8/130874330/tuwudedowonu_vurowog_suzisem.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0437/1460/9305/files/zomodepojofa.pdf
    • https://cdn.shopify.com/s/files/1/0434/4214/3388/files/79063721203.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/81667611697.pdf
    • https://cdn.shopify.com/s/files/1/0430/5109/0077/files/5721221753.pdf
    • https://cdn.shopify.com/s/files/1/0436/5228/4566/files/6666686602.pdf
    • https://cdn.shopify.com/s/files/1/0432/5575/9011/files/14500423626.pdf
    • https://cdn.shopify.com/s/files/1/0429/8850/3203/files/zigow.pdf
    • https://cdn.shopify.com/s/files/1/0434/0567/2597/files/magusikavagegufiz.pdf
    • https://cdn.shopify.com/s/files/1/0454/5898/1022/files/convert_length_units_worksheet.pdf
    • https://cdn.shopify.com/s/files/1/0435/7105/2707/files/33708222589.pdf
    • https://cdn.shopify.com/s/files/1/0432/5448/1058/files/883032902.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0002c41b.bin
c0edfa07cd60577545a77e932cb0f9dff8048149fbeb5d14973a01c34c63d09c
pdf-font-stream PDF embedded font (sfnt) at offset 0x2C41B 5200 bytes
font_01_sfnt_off0002d5b0.bin
44f91ae69c7910505f13e7646521be484aae64dccd9b3ac64b344753accc8678
pdf-font-stream PDF embedded font (sfnt) at offset 0x2D5B0 16052 bytes
font_02_sfnt_off0003077b.bin
a7b1e01542dab829d2ba5dd7846da79335ded9f65a948c274aeb683100f5fd08
pdf-font-stream PDF embedded font (sfnt) at offset 0x3077B 16272 bytes