Malicious PDF — malware analysis report

Static analysis result for SHA-256 d76537ae52594532…

MALICIOUS

PDF

122.7 KB Created: 2020-09-01 05:41:46 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f71bf86cd85b79b727bfdb58d1b29ab6 SHA-1: 4df1cb64efefcb38296c216bae9b0de46a0f9898 SHA-256: d76537ae52594532d665fd5d625ec47c169ea7b62e352359faf56e32ca55e820
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a link to a known malicious redirector, ttraff.cc, disguised as an annual report. The ML classifier strongly indicates maliciousness. The document body, though heavily obfuscated, contains the URL that leads to the malicious redirector. This suggests the primary goal is to redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=university+of+michigan+endowment+annual+report
    • https://cdn.shopify.com/s/files/1/0437/3279/5541/files/mysap_erp_for_dummies.pdf
    • https://cdn.shopify.com/s/files/1/0461/9999/6569/files/murder_mestri_full_movies.pdf
    • https://cdn.shopify.com/s/files/1/0432/6778/4864/files/assignment_sample_format.pdf
    • https://cdn.shopify.com/s/files/1/0432/2210/6271/files/descargar_formato_receta_estandar_sena.pdf
    • https://static.usrfiles.com/ugd/b8c837_5a2b4f95692f4b54b6e802b59bb32fc5.pdf
    • https://static.usrfiles.com/ugd/ec0c41_4ec01451c91742d3a2601da78710d1e1.pdf
    • https://cdn.shopify.com/s/files/1/0431/2596/4957/files/zubujamed.pdf
    • https://cdn.shopify.com/s/files/1/0434/4017/7314/files/add_audio_to_video_online.pdf
    • https://cdn.shopify.com/s/files/1/0431/7180/7391/files/lodedivozajefigu.pdf
    • https://cdn.shopify.com/s/files/1/0433/2558/7609/files/sofeponux.pdf
    • https://static.usrfiles.com/ugd/09c3c7_6b3a5baa99d048cfb364de5f2876fd06.pdf
    • https://static.usrfiles.com/ugd/4b7290_43224a5e03eb44e09b4e2e8c4450e1be.pdf
    • https://static.usrfiles.com/ugd/79e0dc_5520f5c9904c469bab8c6592bb97cd5a.pdf
    • https://static.usrfiles.com/ugd/9ff9b8_93eda2d91a54491a912dd662a0072ad0.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00018d7a.bin
9cca82674559b115de7b52b36acc0794b0e336783ec0a13205926324bc73010e
pdf-font-stream PDF embedded font (sfnt) at offset 0x18D7A 5696 bytes
font_01_sfnt_off0001a0cb.bin
f2978a6977ec231160cb7a84b943e73b6f9b94afc37434f7989bf2b652b745a0
pdf-font-stream PDF embedded font (sfnt) at offset 0x1A0CB 14676 bytes
font_02_sfnt_off0001cefd.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0x1CEFD 4324 bytes