Malicious PDF — malware analysis report

Static analysis result for SHA-256 a62cf32642bb6e39…

MALICIOUS

PDF

244.2 KB Created: 2020-08-29 19:54:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c8495db2044dbce06af1921d405c67cd SHA-1: 26ae20a1a8405c050bb615c47489d5131e5f3177 SHA-256: a62cf32642bb6e392b64aa548f2bdcfbd3a4cddd076cc9adc0b4b71d745de677
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The primary malicious indicator is a PDF link to the known malicious redirector 'ttraff.me'. This suggests the document is intended to redirect users to a malicious site, likely for phishing or malware delivery. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted, and the document body was heavily obfuscated, preventing further analysis of its specific content or intent beyond the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=dnd+5e+stronghold
    • https://cdn.shopify.com/s/files/1/0437/1709/9685/files/pdf_to_microsoft_word_document_converter_online.pdf
    • https://cdn.shopify.com/s/files/1/0435/9802/0767/files/xedawiweg.pdf
    • https://cdn.shopify.com/s/files/1/0429/2778/4099/files/webidejanixowisim.pdf
    • https://cdn.shopify.com/s/files/1/0433/8286/6072/files/sibaguxutudopuban.pdf
    • https://cdn.shopify.com/s/files/1/0436/0273/9362/files/52155047816.pdf
    • https://static.usrfiles.com/ugd/5899d5_f6fc301c3c494404992b18b88f20c798.pdf
    • https://static.usrfiles.com/ugd/b8c837_693ee6fde0234f50981d66cb7a8eb40f.pdf
    • https://static.usrfiles.com/ugd/b8c837_e62dca9eb4164cc580e4e8856dd25dcd.pdf
    • https://static.usrfiles.com/ugd/e3c460_a0923e25b5904fc493a139516caf4e6e.pdf
    • https://static.usrfiles.com/ugd/b8c837_58ab13cd913f46148ffee3d58e94a141.pdf
    • https://static.usrfiles.com/ugd/b8c837_1211ecfa8ab64c55be1b62734e7c30b1.pdf
    • https://static.usrfiles.com/ugd/b8c837_577d03c2bc6a44589703ca04f8528cd5.pdf
    • https://static.usrfiles.com/ugd/724fb5_0f0fb85504314c0292866b8fd45a24c1.pdf
    • https://cdn.shopify.com/s/files/1/0438/5194/0000/files/82117960016.pdf
    • https://cdn.shopify.com/s/files/1/0434/2746/3324/files/24268669764.pdf
    • https://cdn.shopify.com/s/files/1/0438/1576/4125/files/49349508778.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00037f47.bin
7ff03bf453211a9db385da401a4fcd8e4c04af09721f65abf2b677a89b73ebce
pdf-font-stream PDF embedded font (sfnt) at offset 0x37F47 5000 bytes
font_01_sfnt_off0003903e.bin
3a55604f4d72df86bc5b58716f1dec87e7a6c3d3f5c490ec4c0f3a69e42801d1
pdf-font-stream PDF embedded font (sfnt) at offset 0x3903E 16452 bytes