Malicious PDF — malware analysis report

Static analysis result for SHA-256 bbb2cc4cf893da41…

MALICIOUS

PDF

45.3 KB Created: 2020-08-30 09:40:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 37372a65325353d11d568edc1bc44805 SHA-1: 3ff3769c07847d983421b273e76d07798b5ee81c SHA-256: bbb2cc4cf893da419c96286dd95928a4e92b07d259a313e131e5419fcdf65978
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a prominent link to a known malicious redirector, ttraff.cc, disguised as instructions for an 'Illinois form rut-25'. This URL is the primary indicator of malicious intent. The document also features a large number of embedded links, many pointing to static.usrfiles.com, which is flagged as a link farm. The ML classifier strongly supports the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=illinois+form+rut-25+instructions
    • https://static.usrfiles.com/ugd/b8c837_53b723ca448249d7b193bc810be51e90.pdf
    • https://static.usrfiles.com/ugd/41a0b6_3af9b3f0fd54470099d6272b438fabca.pdf
    • https://static.usrfiles.com/ugd/ce14f3_bc1940bca36a4d0c9149aba608e6059d.pdf
    • https://static.usrfiles.com/ugd/b8c837_9010707b508d4fe29e5c843adfd177c3.pdf
    • https://static.usrfiles.com/ugd/73cb9e_10b11bf8f3ad44948bae996e567cd7dc.pdf
    • https://static.usrfiles.com/ugd/b8c837_eb8f0d6663694b40a20dccc2731d356b.pdf
    • https://static.usrfiles.com/ugd/5d2cf3_a4c84a209d1a43e5877455d807e21e7e.pdf
    • https://static.usrfiles.com/ugd/b8c837_41d3e100d03a4617adf6ae15b23b07cc.pdf
    • https://cdn.shopify.com/s/files/1/0437/0425/4615/files/lean_six_sigma_black_belt_exam_questions_and_answers.pdf
    • https://cdn.shopify.com/s/files/1/0428/1021/2518/files/woocommerce_email_template_preview.pdf
    • https://cdn.shopify.com/s/files/1/0451/0508/6616/files/cardiomiopatia_dilatada_canina.pdf
    • https://cdn.shopify.com/s/files/1/0432/3187/1139/files/rebitofizodusisuva.pdf
    • https://cdn.shopify.com/s/files/1/0433/4518/2888/files/search_filter_in_recyclerview_android_example.pdf
    • https://cdn.shopify.com/s/files/1/0429/1022/0447/files/bright_starts_sunnyside_safari_swing_manual.pdf
    • https://cdn.shopify.com/s/files/1/0433/0940/0214/files/4162708462.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000074a7.bin
0ea7e7866ac6689afaf2a067dc202eaf9543c9d001b5ba861b9e316426dd918c
pdf-font-stream PDF embedded font (sfnt) at offset 0x74A7 5040 bytes
font_01_sfnt_off000085bc.bin
3881dca58b22cb6c0abbf0349d03848d8728df328c4dd431c355990d8d3d3cf1
pdf-font-stream PDF embedded font (sfnt) at offset 0x85BC 10176 bytes