Malicious PDF — malware analysis report

Static analysis result for SHA-256 772e6f459094cdfb…

MALICIOUS

PDF

59.5 KB Created: 2020-08-15 00:45:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e794e2bbd94c8c0d21c79ad185765ef9 SHA-1: ffdfc1b3d2b376ddd901197993ee5205e3495151 SHA-256: 772e6f459094cdfb7ea4f5fa9925bb92a436d8e296f837c107865378dd1bdb72
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains multiple embedded URLs, with a critical heuristic identifying a link to known malicious redirector infrastructure at 'https://ttraff.ru/pify?keyword=classical+approaches+to+management+pdf'. The document body, though heavily obfuscated, also contains this URL, suggesting an attempt to manipulate search engine results or direct users to malicious content. The presence of numerous external PDF links further supports the 'PDF_SEO_LINK_FARM' heuristic, indicating a likely spam or phishing campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=classical+approaches+to+management+pdf
    • http://files.nickcutroneo.com/uploads/1/3/1/4/131438442/9206462c9e6ceef.pdf
    • http://files.carlalbertbaseball.net/uploads/1/3/2/8/132815343/f8efc1f7ed014.pdf
    • http://files.gwdancecenter.com/uploads/1/3/0/9/130969572/6154385.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0437/6687/4269/files/15126950724.pdf
    • https://cdn.shopify.com/s/files/1/0433/6222/2232/files/tefefipagojudif.pdf
    • https://cdn.shopify.com/s/files/1/0434/2710/2887/files/contract_extension_agreement.pdf
    • https://cdn.shopify.com/s/files/1/0432/7797/5717/files/anamorphic_format_app_android.pdf
    • https://cdn.shopify.com/s/files/1/0432/8649/5397/files/dediluxo.pdf
    • https://cdn.shopify.com/s/files/1/0434/4853/3142/files/webutofozalorezozefope.pdf
    • https://cdn.shopify.com/s/files/1/0434/2765/9932/files/kujafobikopewito.pdf
    • https://cdn.shopify.com/s/files/1/0437/9040/1687/files/watijodaduzo.pdf
    • https://cdn.shopify.com/s/files/1/0431/2930/7293/files/68816088615.pdf
    • https://cdn.shopify.com/s/files/1/0444/4736/7335/files/sos_slot_pokemon.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000ac45.bin
548d36a1b45069e048a9c0bf67810470d119c0dc6a42dbcb096a503076e6c4f6
pdf-font-stream PDF embedded font (sfnt) at offset 0xAC45 5476 bytes
font_01_sfnt_off0000beb6.bin
9365325f72c77cc8ebfc6e0de9680ef2a2efab37e450152acf45a053f7839d55
pdf-font-stream PDF embedded font (sfnt) at offset 0xBEB6 10016 bytes