Malicious PDF — malware analysis report

Static analysis result for SHA-256 e298f1d90b951956…

MALICIOUS

PDF

51.9 KB Created: 2020-08-20 04:59:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d1b17ff56b27fbfdb41051efe9456653 SHA-1: 9e7e50c06bb251a16257a84e411c49cbefd83377 SHA-256: e298f1d90b951956a543f7b13988beb52edbac3a26ab1405b866a129237c9a54
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link to a known malicious redirector, ttraff.com, which is likely used to distribute further malware or conduct phishing. The document body, though heavily obfuscated, contains the same URL and references to media content, suggesting a lure to entice users to click the malicious link. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=havoc+brothers+kadhalan+song++masstamilan
    • http://files.kauaimusiceducation.org/uploads/1/3/1/4/131410299/lelulonulusuditob.pdf
    • http://files.maisonmeubles.com/uploads/1/3/0/9/130969740/9551114.pdf
    • https://cdn.shopify.com/s/files/1/0432/3190/3902/files/46899780663.pdf
    • https://cdn.shopify.com/s/files/1/0432/6945/6028/files/48822304312.pdf
    • https://cdn.shopify.com/s/files/1/0428/2764/5084/files/32929545829.pdf
    • https://cdn.shopify.com/s/files/1/0449/4747/2552/files/asthma_medications_chart.pdf
    • https://cdn.shopify.com/s/files/1/0438/6534/2117/files/petames.pdf
    • https://cdn.shopify.com/s/files/1/0430/9699/8041/files/pagow.pdf
    • https://cdn.shopify.com/s/files/1/0430/6999/7207/files/zawagasolupe.pdf
    • https://cdn.shopify.com/s/files/1/0438/3830/8512/files/lexanoxomesaxugu.pdf
    • https://cdn.shopify.com/s/files/1/0435/8314/4104/files/woxulabivomubi.pdf
    • https://cdn.shopify.com/s/files/1/0435/6397/4805/files/38914218465.pdf
    • https://cdn.shopify.com/s/files/1/0427/6636/8935/files/27886337026.pdf
    • https://cdn.shopify.com/s/files/1/0429/8299/8170/files/75787779413.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000639e.bin
d9a89ebaea2c8398398a3229f032f079c66fc861866fc9c3f688cdb2399f089e
pdf-font-stream PDF embedded font (sfnt) at offset 0x639E 5580 bytes
font_01_sfnt_off00007667.bin
3402e37cfbd9615ed2302b4a0792b6477c3d118e3fb105d1e2656b06e8e12d8f
pdf-font-stream PDF embedded font (sfnt) at offset 0x7667 14872 bytes
font_02_sfnt_off0000a588.bin
7383a8fbf7e82256cb523b2e7e348a41a62f9f08c75650a02b1572328538cc88
pdf-font-stream PDF embedded font (sfnt) at offset 0xA588 17844 bytes