Malicious PDF — malware analysis report

Static analysis result for SHA-256 c744f0f926520cc4…

MALICIOUS

PDF

123.4 KB Created: 2020-08-31 07:11:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b37a89cf57a92433f2fddc58f08b3e5b SHA-1: ff660587cb3da0af4cd4c8e5c0783de80f004658 SHA-256: c744f0f926520cc42685efb96da02c1773fbbc0e704c283e1a07c7c90b8ca27d
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link to a known malicious redirector, ttraff.ru, which is likely used to direct users to further malicious content. The document body, though heavily obfuscated, contains text related to 'Dragon Ball Z' and the redirector URL, suggesting a lure to entice clicks. The presence of multiple embedded links and the ML classifier's high confidence further support the malicious nature of this document.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=dragon+ball+z+complete+series+free+d
    • https://static.usrfiles.com/ugd/fd3290_4419f81878684743b357c5474f09decb.pdf
    • https://static.usrfiles.com/ugd/b8c837_614345f4df674ab5bdd4266c150813d2.pdf
    • https://static.usrfiles.com/ugd/07625c_78c1bc770675417cb04351071e7d85c1.pdf
    • https://static.usrfiles.com/ugd/66c878_8d6dfeffc00a43ac919c50bef951a518.pdf
    • https://static.usrfiles.com/ugd/5ecadc_075dc3a589b64f66a895260d56faf5f7.pdf
    • https://cdn.shopify.com/s/files/1/0430/4211/1650/files/48945939595.pdf
    • https://cdn.shopify.com/s/files/1/0438/2277/6480/files/29886537454.pdf
    • https://cdn.shopify.com/s/files/1/0437/1388/8405/files/weider_home_gym_models.pdf
    • https://static.usrfiles.com/ugd/97368a_60ed1e62eeaf418a875565c52037ca58.pdf
    • https://static.usrfiles.com/ugd/b8c837_6284ee5ef7f74cc293fa6d99cbb42d45.pdf
    • https://static.usrfiles.com/ugd/3bca44_19aaadf0cc0b4fe28ae4c233f53a9cb2.pdf
    • https://static.usrfiles.com/ugd/b8c837_2fe6e23ca9a04f1699d0d53e64c6856c.pdf
    • https://static.usrfiles.com/ugd/5b9a87_d06b5310dc04461e81853c5dde69c221.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000120a6.bin
bce7a2edc529c5ebe54a875ebb084fd30d75a919122223f7f14711ddd5880fed
pdf-font-stream PDF embedded font (sfnt) at offset 0x120A6 40000 bytes
font_01_sfnt_off00019b49.bin
22b2f9804933fb3f0ce6463dc5d797eb3fb5f20fe83ccce12af36e27072f8559
pdf-font-stream PDF embedded font (sfnt) at offset 0x19B49 5664 bytes
font_02_sfnt_off0001ae70.bin
a1c68180eae955d710b1f59d89b7b5bb1f22246194deffa7b9c3298859733f9b
pdf-font-stream PDF embedded font (sfnt) at offset 0x1AE70 2140 bytes
font_03_sfnt_off0001b848.bin
975c1bb62a16007d1347a212ff4d6c7195d5a174e08cec71f0b36627c55dad5a
pdf-font-stream PDF embedded font (sfnt) at offset 0x1B848 11584 bytes