Malicious PDF — malware analysis report

Static analysis result for SHA-256 866bad4e716cfb98…

MALICIOUS

PDF

45.7 KB Created: 2020-08-21 23:27:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 25f2a6d149216687dbef46d593af400f SHA-1: 89983aaf0b0d5a4fd044b8f3d30a184db718f99e SHA-256: 866bad4e716cfb98ff247370f81f074a2b212f69ee80a16a71281175af183d0e
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a malicious redirector link pointing to 'ttraff.com' with a keyword related to asbestos, suggesting a lure for users seeking specific information. The document body, though heavily obfuscated, contains this URL and other links, indicating an attempt to drive traffic to malicious infrastructure. The ML classifier strongly flagged this PDF as malicious, supporting the assessment of a malicious redirector attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=asbestos+sheet+standard+size
    • http://files.bhurbanhillapartments.com/uploads/1/3/2/6/132683357/c3cc5d0.pdf
    • http://files.washingtonstreetmedical.com/uploads/1/3/0/7/130739112/b57346.pdf
    • http://files.cjstuf.org/uploads/1/3/1/6/131607027/wegijetasudisutad.pdf
    • https://cdn.shopify.com/s/files/1/0430/2045/1997/files/28316455561.pdf
    • https://cdn.shopify.com/s/files/1/0431/4624/8358/files/68938377762.pdf
    • https://cdn.shopify.com/s/files/1/0450/9371/6121/files/goodbye_yellow_brick_road_sara_bareilles.pdf
    • https://cdn.shopify.com/s/files/1/0440/5251/2918/files/16874477733.pdf
    • https://cdn.shopify.com/s/files/1/0434/1347/1384/files/buvori.pdf
    • https://cdn.shopify.com/s/files/1/0434/7530/4612/files/63627702369.pdf
    • https://cdn.shopify.com/s/files/1/0432/0441/1556/files/pubazaxekopitegodulaz.pdf
    • https://cdn.shopify.com/s/files/1/0431/6309/1112/files/employment_legislation.pdf
    • https://cdn.shopify.com/s/files/1/0436/9501/4042/files/xivodaxigas.pdf
    • https://cdn.shopify.com/s/files/1/0431/6856/3355/files/71385166643.pdf
    • https://cdn.shopify.com/s/files/1/0438/4070/0578/files/622753564.pdf
    • https://cdn.shopify.com/s/files/1/0431/9218/9089/files/nagimitadefudejosopewif.pdf
    • https://cdn.shopify.com/s/files/1/0431/5847/0813/files/nodun.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000748b.bin
441aa9ae003c68ec2f19a82063afdb8b12243de8de131a112c6160726e2c9bd9
pdf-font-stream PDF embedded font (sfnt) at offset 0x748B 5060 bytes
font_01_sfnt_off000085af.bin
67d1c18db4703fd4f0373e61dc749a4c62f5ffb9ecfb4d15dbd938f154179832
pdf-font-stream PDF embedded font (sfnt) at offset 0x85AF 10648 bytes