Malicious PDF — malware analysis report

Static analysis result for SHA-256 c5958884112cbd3e…

MALICIOUS

PDF

157.9 KB Created: 2020-08-19 18:59:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1559f5c21a4a9aa6a7694b9d0d33b179 SHA-1: febfe0b3ef706b7e9ff866b85cdf08828f4bcbbb SHA-256: c5958884112cbd3e17344d68e6c75a38c07764d0e39cd4014ac5ef82afdb9873
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a malicious redirector link pointing to 'ttraff.com'. This URL is flagged as malicious and is likely used to lure users to a phishing site or download further malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted, but the primary attack vector is the malicious URL embedded within the document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=sql+tutorial+pdf+tutorialspoint
    • http://dipid.destinylifenetwork.org/uploads/1/3/0/7/130738902/8cae7.pdf
    • http://files.treasurlybydima.com/uploads/1/3/1/4/131411199/buroni.pdf
    • http://xonoveg.alemuwoldemichael.org/uploads/1/3/0/7/130738755/7348180.pdf
    • https://cdn.shopify.com/s/files/1/0435/6279/5171/files/92062735560.pdf
    • https://cdn.shopify.com/s/files/1/0433/3387/7914/files/91597418445.pdf
    • https://cdn.shopify.com/s/files/1/0431/1416/8487/files/pseb_10th_result_2018_repair_form.pdf
    • https://cdn.shopify.com/s/files/1/0434/4456/8216/files/building_maintenance_technology.pdf
    • https://cdn.shopify.com/s/files/1/0434/7199/5033/files/diff_between_cdf_and.pdf
    • https://cdn.shopify.com/s/files/1/0434/7399/3890/files/volkswagen_jetta_owners_manual.pdf
    • https://cdn.shopify.com/s/files/1/0434/3182/1473/files/40321268294.pdf
    • https://cdn.shopify.com/s/files/1/0433/7047/9766/files/92806492539.pdf
    • https://cdn.shopify.com/s/files/1/0433/3397/6223/files/bologna_mappa_centro.pdf
    • https://cdn.shopify.com/s/files/1/0439/2137/5400/files/robomenif.pdf
    • https://cdn.shopify.com/s/files/1/0431/5083/5878/files/9932299366.pdf
    • https://cdn.shopify.com/s/files/1/0428/4389/8019/files/73323571333.pdf
    • https://cdn.shopify.com/s/files/1/0428/2207/4534/files/python_get_file_size.pdf
    • https://cdn.shopify.com/s/files/1/0432/5310/4790/files/3894959702.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000222c4.bin
385e308e7d168835b6af47f24ebb08d7289174728ec3e622ac9c104fe950fbaa
pdf-font-stream PDF embedded font (sfnt) at offset 0x222C4 5264 bytes
font_01_sfnt_off000234b5.bin
92ddb5de135f63ac390d98cd34611c230d48902625bb45d9602996e15695e588
pdf-font-stream PDF embedded font (sfnt) at offset 0x234B5 17032 bytes