Malicious PDF — malware analysis report

Static analysis result for SHA-256 e262a5b2561ecdd6…

MALICIOUS

PDF

45.3 KB Created: 2020-08-29 07:38:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: eafd15b9e3f0f02492af91cf2892143a SHA-1: 2a94293e1caf3d81b7bc8c92da92478c9b4827bb SHA-256: e262a5b2561ecdd6f4cd1c5cab87c18c515703a9d1c5a2f2a2864cba31173030
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, specifically pointing to a lure for 'drivers detective crack'. This link leads to ttraff.ru, which is known malicious infrastructure. The document also contains a mass external PDF link farm, with the dominant host being static.usrfiles.com. The ML classifier strongly flagged this PDF as malicious. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=drivers+detective+crack
    • https://static.usrfiles.com/ugd/b8c837_8c8db09b874642879def5dcbfd0058e2.pdf
    • https://static.usrfiles.com/ugd/b8c837_6b38903ac0944aadbc3783f42a6e28be.pdf
    • https://static.usrfiles.com/ugd/b8c837_2f46307689d54debacfec8c14670a98d.pdf
    • https://static.usrfiles.com/ugd/b8c837_38c8f7ec8ff14a9e93db357aff1485b5.pdf
    • https://static.usrfiles.com/ugd/b8c837_82ffa41a2f0a4ea58ef08650f38e5c37.pdf
    • https://static.usrfiles.com/ugd/b8c837_976822f605494c2280f25cbafcfbd61d.pdf
    • https://static.usrfiles.com/ugd/b8c837_9c7c66be668b4432a4816b250b75f5d3.pdf
    • https://static.usrfiles.com/ugd/b8c837_520695429b8040a68507a86bffe1995b.pdf
    • https://static.usrfiles.com/ugd/b8c837_c8cb7da0ef3f4a4dab8a47c7576dcc1b.pdf
    • https://static.usrfiles.com/ugd/b8c837_757eb45f7b604307b38eaf564db98e1c.pdf
    • https://static.usrfiles.com/ugd/b8c837_4b8fb097159b46f8baa5753c1a57bc4d.pdf
    • https://static.usrfiles.com/ugd/b8c837_3eecc460d65b40b39c20558ba37dc838.pdf
    • https://static.usrfiles.com/ugd/b8c837_1bdc95b42e6642598840b247177bcbaa.pdf
    • https://static.usrfiles.com/ugd/b8c837_847181db77ea4b77923e3445bc95c134.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006529.bin
22aed680bee9b8346c267b92c4d98f22445c2610ba65454b5d6b4da70624dbcb
pdf-font-stream PDF embedded font (sfnt) at offset 0x6529 4596 bytes
font_01_sfnt_off000074de.bin
d286afda7ad4b05034ac9a29115df5ae271bc7d9b53e4640fe5dcac467f4396b
pdf-font-stream PDF embedded font (sfnt) at offset 0x74DE 11592 bytes
font_02_sfnt_off00009a7f.bin
9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x9A7F 4324 bytes