Malicious PDF — malware analysis report

Static analysis result for SHA-256 78be322a28d95cc3…

MALICIOUS

PDF

42.6 KB Created: 2020-08-21 18:02:58 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a8cb0f5c0870cd2337a625e91652d12c SHA-1: 2600820fd6aee347971d4b25b35e7fa8cb53f9f3 SHA-256: 78be322a28d95cc35dbe2dce48a4cf9fe9cb2aa4534ad40e4f58d2e6c9576d56
158 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains an embedded JavaScript stream and multiple external links, including a critical PDF_MALICIOUS_REDIRECTOR_LINK to 'ttraff.com'. This indicates the document is designed to redirect users to malicious infrastructure, likely for further exploitation or phishing. The ML classifier also strongly flagged this PDF as malicious. No specific family was identified, but the techniques suggest a common lure for malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=hey+baby+tamil+video+song
    • http://gugowuw.honorboundco.com/uploads/1/3/0/8/130813821/f6a284.pdf
    • http://xapiro.mysecretmuse.services/uploads/1/3/1/4/131406286/dibaburigobikat.pdf
    • http://files.kamelicounselling.com/uploads/1/3/1/6/131636914/ramuzo_lurinenixidekob_nodamef.pdf
    • http://zidini.rose-annerussell.com/uploads/1/3/1/4/131453459/woluvig-zoradega-fisato-taxaweropazisep.pdf
    • https://cdn.shopify.com/s/files/1/0445/3220/3679/files/tubigadarofunawikez.pdf
    • https://cdn.shopify.com/s/files/1/0431/6191/1458/files/50733257727.pdf
    • https://cdn.shopify.com/s/files/1/0435/5463/5937/files/the_brainiest_insaniest_ultimate_puzzle_book.pdf
    • https://cdn.shopify.com/s/files/1/0434/1976/2855/files/sixth_grade_worksheets.pdf
    • https://cdn.shopify.com/s/files/1/0434/8051/4713/files/rekomendasi_browser_android_ringan.pdf
    • https://cdn.shopify.com/s/files/1/0428/3197/0460/files/83415169335.pdf
    • https://cdn.shopify.com/s/files/1/0431/8671/6830/files/25976852393.pdf
    • https://cdn.shopify.com/s/files/1/0428/1909/2647/files/bjt_transistor_ac_analysis.pdf
    • https://cdn.shopify.com/s/files/1/0437/1772/2280/files/ley_organica_de_la_administracion_publica_federal_2020.pdf
    • https://cdn.shopify.com/s/files/1/0429/7133/2767/files/93783711391.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005134.bin
4bcc937067628209ed3a8eafaa1bd8dc03e36563cba0911326724ef07084ea64
pdf-font-stream PDF embedded font (sfnt) at offset 0x5134 5312 bytes
font_01_sfnt_off00006336.bin
8b2381bb868153a40e326a120b54ff21b2639d347e6c894e07d919f26376c617
pdf-font-stream PDF embedded font (sfnt) at offset 0x6336 2784 bytes
font_02_sfnt_off00006eaa.bin
06a95457b43b0e99b1a3775f9ab5b5d6528f13ec6825d48076684deae05dfd81
pdf-font-stream PDF embedded font (sfnt) at offset 0x6EAA 14508 bytes