Malicious PDF — malware analysis report

Static analysis result for SHA-256 e342ae4c60134e54…

MALICIOUS

PDF

47.4 KB Created: 2020-10-16 18:23:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cf6e4dcfca9602c877e1e25c9391b80c SHA-1: 5159d21d1b43e96412028b83b9ce2b086d6ab4b1 SHA-256: e342ae4c60134e54e9b33f098d0f95939c796e5df562cc4220f776c54f56889c
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous embedded links, with a critical heuristic identifying it as a malicious redirector. The primary malicious URL, https://ttraff.club/123?keyword=handwriting+notes+app+for+android, is likely used to direct users to a phishing or malware-hosting site. The document body, though heavily obfuscated, contains references to URLs, reinforcing the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/123?keyword=handwriting+notes+app+for+android
    • https://cdn-cms.f-static.net/uploads/4368978/normal_5f88db3c601c8.pdf
    • https://cdn-cms.f-static.net/uploads/4365998/normal_5f87194db6cc2.pdf
    • https://cdn-cms.f-static.net/uploads/4369505/normal_5f88bb0887424.pdf
    • https://tetoferapijala.weebly.com/uploads/1/3/1/6/131606168/delekek.pdf
    • https://purolejomi.weebly.com/uploads/1/3/0/7/130776639/4886498.pdf
    • https://keniwuki.weebly.com/uploads/1/3/1/4/131483234/tebavu_mofevuz_punoxibera_gijipomole.pdf
    • https://mumixopid.weebly.com/uploads/1/3/1/8/131872042/woxiwevo.pdf
    • https://cdn.shopify.com/s/files/1/0482/8846/5054/files/jitegawazepofirofevebu.pdf
    • https://cdn.shopify.com/s/files/1/0498/8144/8606/files/cannot_install_apk_android_studio.pdf
    • https://cdn.shopify.com/s/files/1/0432/4347/1008/files/letters_of_recommendation_for_a_principal.pdf
    • https://uploads.strikinglycdn.com/files/f2ca80f9-7fad-4dd1-be12-66252fac1e68/vufodapusebonivowibog.pdf
    • https://uploads.strikinglycdn.com/files/59d759ef-016d-4616-977b-91e5186ba5e6/34289480031.pdf
    • https://uploads.strikinglycdn.com/files/3a8af61b-916e-4270-b217-8f672ee70f78/58271561787.pdf
    • https://uploads.strikinglycdn.com/files/8552868c-c69e-441d-a0b1-a6e73b17c669/lumeripurife.pdf
    • https://uploads.strikinglycdn.com/files/67eebd87-364f-445c-ad92-c34cab4716df/34435828313.pdf
    • https://uploads.strikinglycdn.com/files/53dfef3a-87b7-453d-bfe1-88a5ce274d80/72607683569.pdf
    • https://uploads.strikinglycdn.com/files/21ac3ba8-476d-4429-812d-6790e7b5daaa/xudusezanudu.pdf
    • https://uploads.strikinglycdn.com/files/37fe3501-bb64-4b70-9ad9-4eed22c79913/mejatetivo.pdf
    • https://uploads.strikinglycdn.com/files/501867eb-6c5a-4bba-9aa5-f9b4d90fc61e/mavobavinumedi.pdf
    • https://uploads.strikinglycdn.com/files/61574fb7-8141-44c5-b7f9-2f52b841ef87/4117869008.pdf
    • https://uploads.strikinglycdn.com/files/c1733694-d1cc-462d-a872-7517ab2b5ca1/64224080410.pdf
    • https://uploads.strikinglycdn.com/files/3642720d-dd81-49f3-b320-d7df18b7f963/81047208941.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007b53.bin
cec9dce73f19375d7a3690686063b00e1e8e26fbddc039b05d5b6e203008c2ef
pdf-font-stream PDF embedded font (sfnt) at offset 0x7B53 5232 bytes
font_01_sfnt_off00008d3f.bin
ce940b5d0c59364a34f6b2ff76cabea75939a9d851b209a2eeae2981043b104d
pdf-font-stream PDF embedded font (sfnt) at offset 0x8D3F 10164 bytes