Malicious PDF — malware analysis report

Static analysis result for SHA-256 841f9550c17324a4…

MALICIOUS

PDF

124.8 KB Created: 2020-09-04 19:42:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 37b6cc9445469f35f59bf83e87f8657a SHA-1: da580db4a8fcc7341c184566f71d1395fdc69d98 SHA-256: 841f9550c17324a401aef5d7d4281bd1559b90115ceb6c1ca5fd823c71c597ca
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF was flagged for containing a malicious redirector link and a large number of external links, indicating a link farm. The embedded URL points to 'ttraff.ru', which is identified as malicious infrastructure. While no scripts were explicitly extracted, the PDF structure and heuristics suggest an attempt to lure users to malicious sites, potentially as part of a phishing campaign or to download further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9985

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=narai+juku+japan+guide
    • http://www.opentle.org
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • http://fedorahosted.org/lohit
    • https://static.usrfiles.com/ugd/62e2c1_5af48401b9664d77a788306f4c69c61e.pdf
    • https://static.usrfiles.com/ugd/4bdc6d_4d1d887f5a8c4fc783c02bccf6236caa.pdf
    • https://static.usrfiles.com/ugd/de02f3_151072bbdb344b328b38d8bc8dcfccc1.pdf
    • https://cdn.shopify.com/s/files/1/0454/2873/6168/files/linear_functional_analysis_springer.pdf
    • https://cdn.shopify.com/s/files/1/0462/0134/0057/files/christmas_song_sheet_music.pdf
    • https://cdn.shopify.com/s/files/1/0434/2104/0792/files/lagikisojip.pdf
    • https://cdn.shopify.com/s/files/1/0437/6055/0046/files/27970742660.pdf
    • https://cdn.shopify.com/s/files/1/0435/2193/3466/files/65560506054.pdf
    • https://cdn.shopify.com/s/files/1/0428/1538/9855/files/46364802940.pdf
    • https://cdn.shopify.com/s/files/1/0447/0344/9241/files/xbox_360_usb_explorer.pdf
    • https://cdn.shopify.com/s/files/1/0438/3450/7424/files/the_chainsmokers_closer_lyrics.pdf
    • https://cdn.shopify.com/s/files/1/0437/1746/0120/files/desaxigupi.pdf
    • https://cdn.shopify.com/s/files/1/0432/4661/6733/files/faa_aviation_medical_examiner_guide.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://www.gnu.org/licenses/gpl.html
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License
    • http://scripts.sil.org/OFL

Extracted artifacts 7

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off0000c948.bin
d5c8bccf6fc6b41a9672b3b34704df17fdb4bab9a53e7a0c59fc15a36fc94ae5
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xC948 21940 bytes
stream_006_off00011f87.bin
b1d297ed63ba0f3515e9be22c0ee1a682c9d5402c36894d2022b9b7040cff645
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x11F87 11612 bytes
stream_008_off0001877a.bin
9c74e67df24b9105ed30692ddabc33a83324b235b781ebe3d0aadc29dba14481
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x1877A 31004 bytes
font_01_sfnt_off00010f86.bin
49af902e31c5dbb2c1150369ec8efc6b0cd39413ee05ac0b77b524ab398406e4
pdf-font-stream PDF embedded font (sfnt) at offset 0x10F86 4720 bytes
font_03_sfnt_off00013fa4.bin
1e66b51e6672800daf519d05f1f718caf6c6a119c53d06377da4bb7e5f0f762a
pdf-font-stream PDF embedded font (sfnt) at offset 0x13FA4 27016 bytes
font_05_sfnt_off0001bd4d.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0x1BD4D 4324 bytes
font_06_sfnt_off0001cb4d.bin
532a5e2aee88e8bb1cec7e2cb33fcb1db47112d4df638ef6c86699520ee8192c
pdf-font-stream PDF embedded font (sfnt) at offset 0x1CB4D 7232 bytes