Malicious PDF — malware analysis report

Static analysis result for SHA-256 daae34594cb4d4df…

MALICIOUS

PDF

130.0 KB Created: 2020-08-08 14:05:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 32f13e1182f916ca188a867fcee2f2d6 SHA-1: e35c3d72424584006b8f383eb0d77e224d00de85 SHA-256: daae34594cb4d4df9f185eacc4f4ba7497d87c8af6cb4ef6b844d2d3d75530a6
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'ttraff.ru'. The document body, though heavily obfuscated, also contains this URL. This suggests the primary purpose is to redirect the user to malicious infrastructure, likely for further exploitation or phishing. No scripts were extracted, and the family is unknown due to the lack of specific indicators.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=cardan+shaft+design+calculation+pdf
    • http://files.holycrosscatholicchurch.net/uploads/1/3/0/7/130775658/gebat.pdf
    • http://files.holycrossgo.org/uploads/1/3/0/7/130775429/6526004.pdf
    • http://files.michimathias.com/uploads/1/3/0/8/130813765/1922199.pdf
    • http://files.michcitizenaction.org/uploads/1/3/1/1/131164431/9408221.pdf
    • http://pufewopu.bellecityvet.com/uploads/1/3/0/8/130814124/4876441.pdf
    • https://cdn.shopify.com/s/files/1/0430/3929/3593/files/what_is_arithmetic_logic_unit.pdf
    • https://cdn.shopify.com/s/files/1/0432/7292/9435/files/kuzulo.pdf
    • https://cdn.shopify.com/s/files/1/0440/4209/2694/files/disturbed_sound_of_silence_mp3_download_free.pdf
    • https://cdn.shopify.com/s/files/1/0428/3419/8684/files/73072754080.pdf
    • https://cdn.shopify.com/s/files/1/0430/6285/3794/files/zurotorokaloz.pdf
    • https://cdn.shopify.com/s/files/1/0439/4529/6027/files/91705687278.pdf
    • https://cdn.shopify.com/s/files/1/0430/9227/9445/files/56853038353.pdf
    • https://cdn.shopify.com/s/files/1/0432/9016/5403/files/55492629701.pdf
    • https://cdn.shopify.com/s/files/1/0429/2499/8819/files/gajaxa.pdf
    • https://cdn.shopify.com/s/files/1/0432/9563/7659/files/sufuranosatetoxowejub.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/53446206952.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001992d.bin
a63dc7203ceba2031beaf1d50b83973ffdd0483474384fa5780efc3deacec6ca
pdf-font-stream PDF embedded font (sfnt) at offset 0x1992D 1696 bytes
font_01_sfnt_off0001a157.bin
324f0171e8973855e1a9df3f14254d4431108b15e1b9f39301083a3ae1ce14e6
pdf-font-stream PDF embedded font (sfnt) at offset 0x1A157 5320 bytes
font_02_sfnt_off0001b36d.bin
b12a4cca79ff18343fe492c51dfc31e57b8344ffcaa3a826194a2d1881433109
pdf-font-stream PDF embedded font (sfnt) at offset 0x1B36D 15564 bytes
font_03_sfnt_off0001e485.bin
8385194b8e5b317d3f7e508deafdebb6f4d3d0235293ddc36fb82b940aabe9ff
pdf-font-stream PDF embedded font (sfnt) at offset 0x1E485 16168 bytes