Malicious PDF — malware analysis report

Static analysis result for SHA-256 880137f22cab4aca…

MALICIOUS

PDF

39.9 KB Created: 2020-08-30 04:14:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e5beee85ea81cc81cde9cbe9de94ffcb SHA-1: 077071b9fdd8c5edca741298d8a054fe8703a56a SHA-256: 880137f22cab4aca5d401db2fd5ab617ed16ec2d17f5aa3fac27f65b03693e6a
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, many of which point to a redirector service (ttraff.cc). The document body, though partially corrupted, includes the same URL and a list of other PDF files hosted on static.usrfiles.com, suggesting a link farm or SEO poisoning tactic. The ML classifier strongly flagged this PDF as malicious, and the presence of a malicious redirector link confirms a high likelihood of a phishing or redirection attack. No scripts were extracted, but the PDF structure itself is used for the attack.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=significado+de+lutadora+nata
    • https://static.usrfiles.com/ugd/b65acf_afbc96c58d974acd915551bddaddf39b.pdf
    • https://static.usrfiles.com/ugd/c63dba_b52e5c67f4634db194cc754ca42bbd91.pdf
    • https://static.usrfiles.com/ugd/d55797_28c075a1f37c4dc89f21908954052cbe.pdf
    • https://static.usrfiles.com/ugd/b48b60_86f6b4a992de4e01a69a9f391e9b4228.pdf
    • https://static.usrfiles.com/ugd/0dcf4b_06edae6986cb4de8b81541d7ec580e06.pdf
    • https://static.usrfiles.com/ugd/9ea91e_3ff95b914f1a41db81e73bd8392780db.pdf
    • https://static.usrfiles.com/ugd/b8c837_dd7e36a9b1d546a4b3658a39909a64ec.pdf
    • https://static.usrfiles.com/ugd/ab059d_18be7624be6040e19da96e4c96a02d95.pdf
    • https://static.usrfiles.com/ugd/80c1db_a90a31b8979c4a7a9bd61995762a0f26.pdf
    • https://cdn.shopify.com/s/files/1/0436/2246/5699/files/89991247487.pdf
    • https://cdn.shopify.com/s/files/1/0428/3593/5388/files/16092260862.pdf
    • https://cdn.shopify.com/s/files/1/0430/2045/1997/files/age_of_empires_2_strategy_guide.pdf
    • https://cdn.shopify.com/s/files/1/0431/5381/7749/files/keduvogagogulelewakijaw.pdf
    • https://static.usrfiles.com/ugd/77d535_8b68d787671c48a6b2babcd70089c0a5.pdf
    • https://static.usrfiles.com/ugd/73c254_6aa37ec0742b4f018d55d7930f9818fb.pdf
    • https://static.usrfiles.com/ugd/12f4eb_1508289d06c849fba0f52f9707624a97.pdf
    • https://static.usrfiles.com/ugd/89064d_7483891802a14e019a4b5801e45a9bec.pdf
    • https://static.usrfiles.com/ugd/902d29_9cd16a1f16b646078c09cda06abcf745.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005b09.bin
afc907f3948622032f3122989e3d5392acd4ff2e21242896d73e169bfbb9982c
pdf-font-stream PDF embedded font (sfnt) at offset 0x5B09 5112 bytes
font_01_sfnt_off00006c70.bin
0be2b8ff67fd05eb97df20d5ff6c5e68aa074fc0de3caa75f7dea9aed9c8ae5e
pdf-font-stream PDF embedded font (sfnt) at offset 0x6C70 12060 bytes