Malicious PDF — malware analysis report

Static analysis result for SHA-256 e2973aff3c55dbe3…

MALICIOUS

PDF

203.9 KB Created: 2020-08-08 16:27:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2cdb71da98010350643cde3f9dd080fb SHA-1: b0f875d24aa43112837ba4783bf38a749fc3b46e SHA-256: e2973aff3c55dbe3512590fbb62028f158af7fdd179f63a56ac733d2e6d856fb
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing indicating a malicious redirector link. The ML classifier also flagged the PDF with high confidence. The embedded URL 'https://ttraff.cc/pify?keyword=list+of+astm+international+standards+pdf' is the primary indicator of malicious intent, likely leading to a phishing or malware download site. No scripts were extracted, but the PDF structure itself is used for the malicious redirection.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9995

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=list+of+astm+international+standards+pdf
    • http://files.vosspecans.com/uploads/1/3/1/4/131412362/zobonimufoj-betuwu.pdf
    • http://files.ensokitchensomd.com/uploads/1/3/0/8/130874161/5fae6ac001a.pdf
    • http://files.mshsiao.com/uploads/1/3/1/4/131453450/8ebd0bb1.pdf
    • http://files.simplegiftssyrupandsalmon.com/uploads/1/3/0/9/130969312/7823327.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/45366335679.pdf
    • https://cdn.shopify.com/s/files/1/0434/5508/6742/files/vunikajima.pdf
    • https://cdn.shopify.com/s/files/1/0429/9839/9139/files/50126317334.pdf
    • https://cdn.shopify.com/s/files/1/0429/7018/5879/files/gisolajuvalewirop.pdf
    • https://cdn.shopify.com/s/files/1/0449/8276/3679/files/swing_trading_for_beginners.pdf
    • https://cdn.shopify.com/s/files/1/0431/9156/6493/files/anexo_1_oaci.pdf
    • https://cdn.shopify.com/s/files/1/0430/5800/4117/files/75419458964.pdf
    • https://cdn.shopify.com/s/files/1/0451/4463/7605/files/cartesian_coordinate_system_worksheet.pdf
    • https://cdn.shopify.com/s/files/1/0436/9947/0490/files/80420540647.pdf
    • https://cdn.shopify.com/s/files/1/0440/1886/0190/files/532746311.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0002c48f.bin
b55049c5a01ee855af1399f8fce9e00a9e6f9dd5af3c82f6a41c6d54ce8fcc32
pdf-font-stream PDF embedded font (sfnt) at offset 0x2C48F 2900 bytes
font_01_sfnt_off0002cee9.bin
0a65ce0646b618e6f586017b118816c2c8fb0b901e0923d0c40ca1907ad058ea
pdf-font-stream PDF embedded font (sfnt) at offset 0x2CEE9 4916 bytes
font_02_sfnt_off0002df7c.bin
9a32e7ab30fffe5ab33bf05685e8a906642f9168c59f441bbc7702421a01894b
pdf-font-stream PDF embedded font (sfnt) at offset 0x2DF7C 16728 bytes
font_03_sfnt_off000312cd.bin
7f6049e5011acf0e8581793f2bc2bb947aac2929fdb77abc318b2a6155c1ef71
pdf-font-stream PDF embedded font (sfnt) at offset 0x312CD 4324 bytes