Malicious PDF — malware analysis report

Static analysis result for SHA-256 81f6c6630ae4f1b6…

MALICIOUS

PDF

321.2 KB Created: 2020-08-19 06:06:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a1c18a4d189552401d528fed5e282b85 SHA-1: 2a97acdb40272584d5689e21c2a31d4bb3bfae59 SHA-256: 81f6c6630ae4f1b6c951113454e286d8e9035a931518080858e7b7322bd64e01
64 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a heuristic firing for a malicious redirector link pointing to 'ttraff.ru'. The document body, though heavily obfuscated, contains the same URL, suggesting it's the primary lure. The file's purpose appears to be directing users to this malicious site, likely as part of a phishing or malware delivery scheme.

Machine Learning

  • Nyx PDF Classifier clean score 0.0765

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=original+bible+pdf+free
    • http://files.thekeytotorah.com/uploads/1/3/1/8/131857717/dixutuvoxe.pdf
    • http://miwoxaj.acollinsedu.com/uploads/1/3/1/4/131437619/a00900.pdf
    • http://files.sankofaoutreach.org/uploads/1/3/1/3/131380915/penagamavurul.pdf
    • http://files.meowmeowpowpowlit.com/uploads/1/3/1/4/131483143/3849451.pdf
    • http://files.harrytadd.co.uk/uploads/1/3/1/3/131398195/mepodofezalad.pdf
    • http://www.opentle.org
    • http://fedorahosted.org/lohit
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102Hussain
    • http://smc.org.inhttp://smc.org.in
    • http://www.fontrix.comhttp://www.nhncorp.com
    • http://www.indictrans.org
    • http://www.thdl.org/http://www.thdl.org/Tibetan
    • https://cdn.shopify.com/s/files/1/0434/3051/0742/files/ferritin_test_lab_report.pdf
    • https://cdn.shopify.com/s/files/1/0431/8173/6096/files/giteridilunojokikesogopab.pdf
    • https://cdn.shopify.com/s/files/1/0431/5188/4445/files/wolokasaseb.pdf
    • https://cdn.shopify.com/s/files/1/0432/5595/5619/files/ganubufufatelugixev.pdf
    • https://cdn.shopify.com/s/files/1/0437/6163/1384/files/sbi_clerk_exam_syllabus_2020.pdf
    • https://cdn.shopify.com/s/files/1/0434/3762/1404/files/lebusezobamafanasateden.pdf
    • https://cdn.shopify.com/s/files/1/0429/3387/8940/files/suxepapo.pdf
    • https://cdn.shopify.com/s/files/1/0431/0096/2967/files/craftsman_ys_4500_manual.pdf
    • https://cdn.shopify.com/s/files/1/0439/3458/0891/files/arcswat_manual_espaol.pdf
    • https://cdn.shopify.com/s/files/1/0434/6766/9654/files/30140147293.pdf
    • https://cdn.shopify.com/s/files/1/0434/4283/1522/files/pre_algebra_worksheets_grade_6.pdf
    • https://cdn.shopify.com/s/files/1/0431/4667/4337/files/juvumipiwub.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://www.gnu.org/licenses/gpl.html
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL
    • https://gitlab.com/smc/meera/blob/master/COPYING
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNU
    • http://www.gnu.org/copyleft/gpl.htmRegular
    • http://sinhala.sourceforge.net/
    • http://sinhala.cvs.sourceforge.net/viewvc/*checkout*/sinhala/sinhala/fonts/CREDITS
    • http://www.gnu.org/licenses/gpl-2.0.html
    • http://www.gnu.org/licenses/lgpl.htmlRegularDanhHong
    • http://www.geocities.com/dnhhng
    • http://scripts.sil.org
    • http://www.gnu.org/copyleft/gpl.htmlTibetan

Extracted artifacts 23

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off000215fe.bin
53538c470c305d924b2ec4dd8e0d860633d62be77a7f207e95c657e4a4b46ad2
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x215FE 13760 bytes
stream_012_off00030a7f.bin
0dc056e4df5e63501e4879a923373d75f3389cbe5470967e3c95bd7711a9ed61
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x30A7F 10224 bytes
stream_014_off000362be.bin
bea0914aa74625b27df0fd9dac100e6e93defafba8abf170d5b87cae8341b45e
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x362BE 38388 bytes
font_00_sfnt_off00020324.bin
4d649eb33d9e86e629a44e6b9847fc366f26d1edab60ff87f6fef1253f363c86
pdf-font-stream PDF embedded font (sfnt) at offset 0x20324 4996 bytes
font_02_sfnt_off00023c7e.bin
b4cf7d618ecdadf6339b558576cac64d794d7bc41f080c5195ace90fa86b387d
pdf-font-stream PDF embedded font (sfnt) at offset 0x23C7E 6812 bytes
font_03_sfnt_off0002542c.bin
2219f407d6a659a96d1edaf9ee29d847022dec0eacb0715a7281aa6a3c3a7c2d
pdf-font-stream PDF embedded font (sfnt) at offset 0x2542C 45288 bytes
font_04_sfnt_off0002be52.bin
4a23e48dcc7af2a879a7d581d54dfbd37a532f19d922a4e29387a6edde0f5e91
pdf-font-stream PDF embedded font (sfnt) at offset 0x2BE52 5200 bytes
font_05_sfnt_off0002d005.bin
2e728541761a870941519d667ab0224fd9b406321bceaeb046aaa18ba3a7953a
pdf-font-stream PDF embedded font (sfnt) at offset 0x2D005 2940 bytes
font_06_sfnt_off0002dc45.bin
397838006f5ddacad12919cf1229af8f27e1a5c7a096ad49aa51044be6c5861a
pdf-font-stream PDF embedded font (sfnt) at offset 0x2DC45 7120 bytes
font_07_sfnt_off0002f4a7.bin
75830b4db16f943a74b28947c6dcac63311551fbaf00bbb266b7401b557a85ce
pdf-font-stream PDF embedded font (sfnt) at offset 0x2F4A7 7352 bytes
font_09_sfnt_off0003285c.bin
bbff4bd0c76c548d3c04bd3354186c98291acf2ee91b8ea2f2c79273f6c4fc29
pdf-font-stream PDF embedded font (sfnt) at offset 0x3285C 18572 bytes
font_11_sfnt_off0003b517.bin
fd09a0753748dd8c6eadd56dfc73e0ac2107f718178315a66b3e04940ae7709e
pdf-font-stream PDF embedded font (sfnt) at offset 0x3B517 3560 bytes
font_12_sfnt_off0003c173.bin
d5de4d1432c797bb80581a8182418c317e7c8af116758355f0edb7cc4151660d
pdf-font-stream PDF embedded font (sfnt) at offset 0x3C173 9240 bytes
font_13_sfnt_off0003d879.bin
144fa451fcf20fb387b36a6a69bd91d0c7db10b0f3f39f6426d6596f0f16dcbb
pdf-font-stream PDF embedded font (sfnt) at offset 0x3D879 9236 bytes
font_14_sfnt_off0003f679.bin
a5d2b426e748de1835db9a36efbf9146d6d6e4ca491cb342a6dbf474d83c4a6c
pdf-font-stream PDF embedded font (sfnt) at offset 0x3F679 5172 bytes
font_15_sfnt_off0004082b.bin
6da1137baa2718a5e4db351dcc708cedf177e1f102f01380ebb137ac8971b6e6
pdf-font-stream PDF embedded font (sfnt) at offset 0x4082B 13860 bytes
font_16_sfnt_off00042aef.bin
40684d3f7f315dce62a22ae6f9f5aa9edec3590940905f9e6dc74415f91ef40b
pdf-font-stream PDF embedded font (sfnt) at offset 0x42AEF 14704 bytes
font_17_sfnt_off00044f71.bin
a6cb17fb1937a55e00347883ddd4ad19cf8e3b38cf03dae863c7c83a6f827391
pdf-font-stream PDF embedded font (sfnt) at offset 0x44F71 5252 bytes
font_18_sfnt_off00046052.bin
5c04e2806ccbf1165897861cc2ff4b523aef99955f6bda33b6a53233588516eb
pdf-font-stream PDF embedded font (sfnt) at offset 0x46052 8376 bytes
font_19_sfnt_off00047a13.bin
503d069fb89b4c46109658bc57685003caa7eb2f3f0dbbc08f87bf5a99c9f0e6
pdf-font-stream PDF embedded font (sfnt) at offset 0x47A13 2128 bytes
font_20_sfnt_off0004832d.bin
842f3da2fee92f4831e84c01e723cc9bfad7fcc6e6466429c02761bbfe9de034
pdf-font-stream PDF embedded font (sfnt) at offset 0x4832D 19468 bytes
font_21_sfnt_off0004b66d.bin
c84a3a7383f56f8c73cfb8cf7d158dcf54c4d77d6675160c08f066a9f854a7d7
pdf-font-stream PDF embedded font (sfnt) at offset 0x4B66D 8540 bytes
font_22_sfnt_off0004cf1a.bin
29d30a9d7da32e1f490eaee681aa0a3baca1d1bf5f66bc9be6fc70cc3bd1e5b5
pdf-font-stream PDF embedded font (sfnt) at offset 0x4CF1A 14120 bytes