Malicious PDF — malware analysis report

Static analysis result for SHA-256 a2c287275cf4e7a6…

MALICIOUS

PDF

219.3 KB Created: 2020-09-08 14:33:30 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 163f18ca263d04bd097dbc04677eb8a6 SHA-1: f0555926d8b672b7b15af4451ed0c03009076608 SHA-256: a2c287275cf4e7a648a0091ff570b6d00a858c440115326e7acc315aaa039539
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a critical heuristic firing indicating a link to known malicious redirector infrastructure. The ML classifier also flagged the document with high confidence. The embedded URL, https://ttraff.cc/pify?keyword=european+endocrine+society+guidelines+adrenal+incidentaloma, is the primary indicator of malicious intent, likely leading to a phishing or malware distribution site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=european+endocrine+society+guidelines+adrenal+incidentaloma
    • https://static.usrfiles.com/ugd/b8c837_0dc2bb375e19499ba24623f6837afb66.pdf
    • https://static.usrfiles.com/ugd/3b5dd9_6cda5df98f47448b8f0ce043a34f714f.pdf
    • https://static.usrfiles.com/ugd/9b7d8a_429f2291dc1b49d89b873001a237fe52.pdf
    • https://static.usrfiles.com/ugd/5fd5c1_020fc59732834902aca385b0abcd0754.pdf
    • https://static.usrfiles.com/ugd/9421c8_ce474aa5a69e4cd2a0ca5e5b7bd95b21.pdf
    • https://static.usrfiles.com/ugd/debdc1_817e0bb294814123836725f80439c4e0.pdf
    • https://static.usrfiles.com/ugd/8a419d_83780e7d1fb24906a153c686d386ba34.pdf
    • https://static.usrfiles.com/ugd/8b49c6_6b6af992c3414b87805c89957549b060.pdf
    • https://static.usrfiles.com/ugd/15cd4d_94f58d34d3ac46a18cd85f4af4407f73.pdf
    • https://static.usrfiles.com/ugd/3ceeb9_be5f6b224a524ff694867f44a3b06ccd.pdf
    • https://static.usrfiles.com/ugd/ef253e_85f05549a8d84940b39a02ca009973f0.pdf
    • https://static.usrfiles.com/ugd/9ff9b8_a61e0314745249fba59c90dd84b99085.pdf
    • https://static.usrfiles.com/ugd/3bf302_44b1db01b1b14a48b33ecbc189f60727.pdf
    • https://static.usrfiles.com/ugd/45e30f_6dff4cab7a8048e7a9ebd03d4d87258d.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0003062e.bin
d74b025d1ad0b5820fc8ce8f9fe628408a3e7ff5bb62f8713062b0e367fa8cfe
pdf-font-stream PDF embedded font (sfnt) at offset 0x3062E 5452 bytes
font_01_sfnt_off000318b0.bin
dd62830a5f8410f5dab6dc643a3b40795e64fa93b41a84d8ca67c33cf6cab0fd
pdf-font-stream PDF embedded font (sfnt) at offset 0x318B0 15524 bytes
font_02_sfnt_off000348ad.bin
36ed9caf719e0849df8fd87ade7d51f3d04b8af5454f1aaa896d38a56b473f78
pdf-font-stream PDF embedded font (sfnt) at offset 0x348AD 16272 bytes