Malicious PDF — malware analysis report

Static analysis result for SHA-256 7ce205fffb2b30fc…

MALICIOUS

PDF

87.9 KB Created: 2020-09-05 02:59:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ecaa077be7cc5aa85c9d6dcb0c91b15f SHA-1: 97362ce2926c71aade44660c104574a9c09e30a6 SHA-256: 7ce205fffb2b30fc7df1cd6b129d92aefca694075e34ff6e3bda68c3536e962f
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'ttraff.club'. This URL is presented within the document body, disguised as a link to help solve cubic equations. The ML classifier also strongly flagged this PDF as malicious. The primary attack vector appears to be social engineering, directing users to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=solving+cubic+equation+pdf
    • https://static.usrfiles.com/ugd/78daac_2062f96dccdf43aa87b76fff371d88db.pdf
    • https://static.usrfiles.com/ugd/e643da_87e7e265cbb940c68fb4b947b037530a.pdf
    • https://static.usrfiles.com/ugd/0df15e_777e34fa9ed44da4a34f0dda4e656312.pdf
    • https://static.usrfiles.com/ugd/dcbeda_17c3eb2f6baf4ae3a8e71dfae22fb297.pdf
    • https://static.usrfiles.com/ugd/ced2dc_cb49bd38501443318d5673f218714b4c.pdf
    • https://cdn.shopify.com/s/files/1/0465/5008/9878/files/benim_hocam_tarih_konu_anlatm_2020.pdf
    • https://cdn.shopify.com/s/files/1/0435/7249/4495/files/web_design_full_course_download.pdf
    • https://cdn.shopify.com/s/files/1/0427/5883/2294/files/dont_knock_twice_game_ending_explained.pdf
    • https://cdn.shopify.com/s/files/1/0440/1519/0181/files/ios_7._2._1_apps_free.pdf
    • https://cdn.shopify.com/s/files/1/0438/6275/3445/files/worugijojetosafixalugu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f6b8.bin
f8496c42a2d0f40cfe01fc4f0e0c09c8c25f9149f6647383966f9460643c679c
pdf-font-stream PDF embedded font (sfnt) at offset 0xF6B8 5480 bytes
font_01_sfnt_off00010975.bin
a0f6940fa2deb53e3c804a5c0fb3bbd9db401a8074b503ed931244cac892bf1a
pdf-font-stream PDF embedded font (sfnt) at offset 0x10975 16580 bytes
font_02_sfnt_off00013d9c.bin
84f14f72235fb3b9cb2c6e906e67060b3123b14d3bfb58cd687b6aa2884134ec
pdf-font-stream PDF embedded font (sfnt) at offset 0x13D9C 16148 bytes