Malicious PDF — malware analysis report

Static analysis result for SHA-256 85d15e993b0b1579…

MALICIOUS

PDF

41.4 KB Created: 2020-09-01 01:01:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: aabb7c579fec98b36e5e916eafdf31dd SHA-1: e73c88329910aefb9ffc71a811cf448ba92de7c9 SHA-256: 85d15e993b0b1579c52bea06408edc77d52ec8f8da844b6a61b5dd867107c142
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a heuristic firing for linking to known malicious redirector infrastructure, specifically 'ttraff.cc'. It also exhibits characteristics of a PDF link farm, containing numerous external PDF links. While no scripts were directly extracted, the presence of embedded URLs and the nature of the heuristics suggest an attempt to redirect users to potentially malicious content, likely as part of a phishing or scam campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=giza+cotton+vs+bamboo+sheets
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://static.usrfiles.com/ugd/804ff6_ace6603d46bb4e3aa2f47c5a817b07da.pdf
    • https://static.usrfiles.com/ugd/b8c837_e97a4c2bb7ae48c3aba4fe4fdf46d109.pdf
    • https://static.usrfiles.com/ugd/b8c837_8079d3709d934b1dbd5ba152368b8f20.pdf
    • https://static.usrfiles.com/ugd/bfbc46_d29a8f157fda470ca2283b23095d30ee.pdf
    • https://static.usrfiles.com/ugd/10e3af_a66cf365daa74a5ab6fd026c6f74107b.pdf
    • https://static.usrfiles.com/ugd/5af86b_7f8039aef42b42baa5ec7c87f6608b64.pdf
    • https://static.usrfiles.com/ugd/b8c837_96d04563b91e43d4904875a785eaa00c.pdf
    • https://static.usrfiles.com/ugd/a91264_d342b58b35184e768255cb6dc178918d.pdf
    • https://cdn.shopify.com/s/files/1/0433/7516/5594/files/79107682662.pdf
    • https://cdn.shopify.com/s/files/1/0428/0975/3767/files/37375184295.pdf
    • https://static.usrfiles.com/ugd/b8c837_f72259117af24ee7bd0d4a59a6a7b8a7.pdf
    • https://static.usrfiles.com/ugd/fb83f1_4b633311da734da7bbb71ceffeb22546.pdf
    • https://static.usrfiles.com/ugd/c162b3_7f1a1d9898264ce2bf9081c8da5ef63b.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000063da.bin
51d10c0616ff54a8fe1eff54677e43f6b3a98fda682c3f1f78a20d36a2afeda5
pdf-font-stream PDF embedded font (sfnt) at offset 0x63DA 5192 bytes
font_01_sfnt_off00007576.bin
9a149f7fa9f58dc83d75189e0f6b9032373c833f1ebe5055e7efc97fa72233f9
pdf-font-stream PDF embedded font (sfnt) at offset 0x7576 10256 bytes