Malicious PDF — malware analysis report

Static analysis result for SHA-256 6a377c4d9b5f3b8d…

MALICIOUS

PDF

176.7 KB Created: 2020-09-20 07:52:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 533ab4afe45b38d2e4b5120ea8f3f4c5 SHA-1: 6546d3669ac8f8336ea3b6771aacfc273a914f2c SHA-256: 6a377c4d9b5f3b8d7ee6a86ad43ca21f4937b6d37969d9384c22afef46bb4b0a
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.cc'. This indicates the document's primary purpose is to redirect users to a potentially harmful website. While no scripts were extracted, the presence of the malicious URL is a strong indicator of a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wb?keyword=persona%203%20kenji%20location
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0437/1261/0457/files/64083342160.pdf
    • https://cdn.shopify.com/s/files/1/0430/6652/3809/files/hotel_california_tabs_capo.pdf
    • https://cdn.shopify.com/s/files/1/0437/3633/4501/files/guidelines_for_developmental_coordination_disorder_uk.pdf
    • https://cdn.shopify.com/s/files/1/0433/9800/4899/files/xutobobepoxuzubane.pdf
    • https://cdn.shopify.com/s/files/1/0437/0841/6165/files/74383505401.pdf
    • https://cdn.shopify.com/s/files/1/0438/9994/5112/files/wurijirawumerezuviduno.pdf
    • https://cdn.shopify.com/s/files/1/0432/5359/6310/files/kemutitesexediw.pdf
    • https://cdn.shopify.com/s/files/1/0430/8202/3061/files/walmart_apply_online.pdf
    • https://cdn.shopify.com/s/files/1/0439/5424/1694/files/luwuwate.pdf
    • https://6e9d004e-55df-445b-af38-5c47361f8be2.filesusr.com/ugd/405339_8fef814695294250b054b0db4a939fff.pdf?index=true
    • https://0499d8e5-c318-47df-bfba-f74fa942e351.filesusr.com/ugd/405339_01739cffbe774638a8fc726505293fd9.pdf?index=true
    • https://b92b530a-636d-4446-8d65-a4f198162a65.filesusr.com/ugd/1be480_1f7d3a4897af4789a80692c3cb9b7fce.pdf?index=true
    • https://f3072a6b-57d1-45c7-a70d-2b3c80c09bb9.filesusr.com/ugd/21e9e0_d50d7ceb83f44c71a66e07cba2b2bc62.pdf?index=true
    • https://08445d65-a651-4d2a-8159-2a5b94d5c809.filesusr.com/ugd/c12414_d761858be0d042f68784e237a8b62720.pdf?index=true
    • https://436bdcda-0055-4bb9-a307-1496f642203a.filesusr.com/ugd/c6ac46_f6966408ea4d4e5a9aa06d87ca4fc58e.pdf?index=true
    • https://801964ee-9b7c-4837-b1bf-607a50424e47.filesusr.com/ugd/ceb2e8_3b270aa4e6494b17af829ad3df584b55.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001ad21.bin
446ec8f695c8761b23553e51602c89f72570a09e7a1f856ad28c503f04cbd89b
pdf-font-stream PDF embedded font (sfnt) at offset 0x1AD21 69960 bytes
font_01_sfnt_off00027ec4.bin
b73aa8088b8c6de7dc7377fdc8e0f476705dee0d2e7523b4bf2c88bc89dbb9a4
pdf-font-stream PDF embedded font (sfnt) at offset 0x27EC4 5100 bytes
font_02_sfnt_off0002902d.bin
4e2dbf54f86a2a25715ba2fb81c526881c46e55f0cd6c19139829b1010f96a79
pdf-font-stream PDF embedded font (sfnt) at offset 0x2902D 10744 bytes