Malicious PDF — malware analysis report

Static analysis result for SHA-256 ed5268a24fc2acd8…

MALICIOUS

PDF

34.9 KB Created: 2020-10-31 17:15:19 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1fa48d2528865c892b2b3f38294dd550 SHA-1: 013d8a32bbd4fa85b4b0d436e807680de7a5ad81 SHA-256: ed5268a24fc2acd8389dc0f014f21cbc1d9796996f14e6e50333a528e37ad17b
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a critical heuristic firing indicating it links to known malicious redirector infrastructure. The embedded URL, 'https://ttraff.com/123?keyword=practice+reflection+worksheet+examples', is the primary indicator of malicious intent. Although the document body contains text related to 'practice reflection worksheet examples', this appears to be a lure to disguise the malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9991

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/123?keyword=practice+reflection+worksheet+examples
    • https://cdn-cms.f-static.net/uploads/4404500/normal_5f954bc913a61.pdf
    • https://cdn-cms.f-static.net/uploads/4371536/normal_5f967da483037.pdf
    • https://cdn-cms.f-static.net/uploads/4367665/normal_5f910b2c8c4e9.pdf
    • https://cdn-cms.f-static.net/uploads/4414678/normal_5f969d2281d8c.pdf
    • https://cdn-cms.f-static.net/uploads/4382617/normal_5f916665b3ac9.pdf
    • https://cdn-cms.f-static.net/uploads/4367283/normal_5f9c04a5dae91.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/matogapibelifiv/xorutakajusa.pdf
    • https://cdn.shopify.com/s/files/1/0495/5720/9240/files/bobazodoluwut.pdf
    • https://cdn.shopify.com/s/files/1/0504/4279/7210/files/mojonaloposekonewipejaxoj.pdf
    • https://s3.amazonaws.com/kudufigunabi/suzisozirizap.pdf
    • https://s3.amazonaws.com/ganubatebedoxez/building_construction_layout_procedures.pdf
    • https://s3.amazonaws.com/gebukil/wevemobixodasup.pdf
    • https://s3.amazonaws.com/joterige/95590910365.pdf
    • https://cdn.shopify.com/s/files/1/0496/5400/5911/files/sebezosa.pdf
    • https://s3.amazonaws.com/sugaguxagu/dojawaxemitofolubasobada.pdf
    • https://cdn.shopify.com/s/files/1/0500/3490/1145/files/sonos.pdf
    • https://s3.amazonaws.com/sugosubexez/convert_to_midi.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000063e0.bin
59530673862d1f0f60a80930160dee33ddb3ede197a38ad75600c20231b2aedb
pdf-font-stream PDF embedded font (sfnt) at offset 0x63E0 5480 bytes