Malicious PDF — malware analysis report

Static analysis result for SHA-256 eed9f8ba7d41afd3…

MALICIOUS

PDF

41.5 KB Created: 2020-08-31 23:42:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fc0049470f5d459ced642a4cdd54789d SHA-1: b8e333ca2f1bf5e3cb4f5f8b59b609e1d2841daa SHA-256: eed9f8ba7d41afd3d6b7bcdd9c6ac1f1fe0b47874b597793acdb4d98dde3105c
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=trasformazione+da+atmosfera+a+pascal'. Additionally, it features a PDF link farm heuristic, indicating a large number of external links, with 'https://static.usrfiles.com/ugd/5899d5_29ddb25cdef244d9a20773880b9d09d2.pdf' being the first in the list. The ML classifier also strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains the malicious URL and other PDF links.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=trasformazione+da+atmosfera+a+pascal
    • https://static.usrfiles.com/ugd/5899d5_29ddb25cdef244d9a20773880b9d09d2.pdf
    • https://static.usrfiles.com/ugd/837d34_a3ee0d3f0d06482c9b6f126e396a82a3.pdf
    • https://static.usrfiles.com/ugd/b8c837_fe0b654dd6f3450fa4922c0acb5911b7.pdf
    • https://static.usrfiles.com/ugd/7f929b_9e94e122beb44924b6fa829085173f6b.pdf
    • https://static.usrfiles.com/ugd/565485_644b168194214e5a9c170392d3483d5c.pdf
    • https://static.usrfiles.com/ugd/73c254_61d2fef562734de0955d823cac463a98.pdf
    • https://static.usrfiles.com/ugd/1f2646_8c5fef4690344c33956cb9bba5573b4e.pdf
    • https://static.usrfiles.com/ugd/a64c8c_0bdbf0057de749bf8c2096905f348fb3.pdf
    • https://static.usrfiles.com/ugd/b7ab08_ebffb786bc1f44849caa5397f77b1329.pdf
    • https://static.usrfiles.com/ugd/e5a943_c2c5280d14eb450688872dfe7bc42027.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000055c3.bin
d71d4e23222803933feb21355e84c26362bee0a05f9beb555613905e8b4c839c
pdf-font-stream PDF embedded font (sfnt) at offset 0x55C3 5088 bytes
font_01_sfnt_off000066ef.bin
43c609d57d85972dfd792a6f58e60263777668d54be218de06032a77aef57cef
pdf-font-stream PDF embedded font (sfnt) at offset 0x66EF 11152 bytes
font_02_sfnt_off00008b4a.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0x8B4A 4324 bytes