Malicious PDF — malware analysis report

Static analysis result for SHA-256 d32d95b0448c5cc6…

MALICIOUS

PDF

54.4 KB Created: 2020-08-31 01:43:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f531c160abd9f0697f478f6a31a1ee78 SHA-1: 65ff60c20d3645bb7bcccf1abbd73fca0ee4ea2f SHA-256: d32d95b0448c5cc62d5046e115832e041de6ddd5cfbc2cc54c76df7b6d136903
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.ru'. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded URLs, many hosted on 'static.usrfiles.com'. The ML classifier also strongly indicated maliciousness. The primary attack vector appears to be luring the user to click the malicious link, which likely leads to a phishing or malware download page.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=klassisk+kelly+bl%25C3%25A5+bog
    • https://static.usrfiles.com/ugd/67e251_9087f84cdb1d482ab9849a5ed73df07f.pdf
    • https://static.usrfiles.com/ugd/77eba6_5132b9bf549840e4ba67c177aceaaa8e.pdf
    • https://static.usrfiles.com/ugd/b8c837_93d65f0bb7244ba693c62d5be9983a4c.pdf
    • https://static.usrfiles.com/ugd/b8c837_c5751e6bda844f2b8fa809d0d9be069e.pdf
    • https://static.usrfiles.com/ugd/07625c_99558ec85490436e8afd667f71cbf0bd.pdf
    • https://static.usrfiles.com/ugd/badafb_fc1b527396c948879cee5df31901dc90.pdf
    • https://static.usrfiles.com/ugd/865d50_76c50c7f333d41f6a52f1dcdb61f7471.pdf
    • https://static.usrfiles.com/ugd/b8c837_60c32697e40e47429aa316643a28fa53.pdf
    • https://static.usrfiles.com/ugd/b88e3d_0cba709091ee431d82ade12430d911ee.pdf
    • https://static.usrfiles.com/ugd/b8c837_2e0839b1a2534d9abba6fd66bce1cfb6.pdf
    • https://static.usrfiles.com/ugd/906e9f_657316edacb549c8934ae4e74ea5ddd0.pdf
    • https://static.usrfiles.com/ugd/7f16bd_e511829a47664d7ea4f3eb004cb072df.pdf
    • https://cdn.shopify.com/s/files/1/0432/3940/7784/files/zovanikuzizupirowavape.pdf
    • https://cdn.shopify.com/s/files/1/0438/0593/3730/files/90011763184.pdf
    • https://cdn.shopify.com/s/files/1/0430/2195/9325/files/39347894618.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000786b.bin
b3ca01da4c0b4dd12d1f32459eda51bed0fbeb8bbd865aa6d2ec41a6e909fffe
pdf-font-stream PDF embedded font (sfnt) at offset 0x786B 4940 bytes
font_01_sfnt_off000088a7.bin
5bd4cc939efbdecfeffeedcf6886f90fcd5d2a48532e137c09589e126627e16a
pdf-font-stream PDF embedded font (sfnt) at offset 0x88A7 17380 bytes
font_02_sfnt_off0000bca7.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0xBCA7 4324 bytes