Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe732822454a6903…

MALICIOUS

PDF

74.9 KB Created: 2020-09-09 18:58:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2f33911ace12ca6c1056bc70f56943a8 SHA-1: 4554d3f43b38edd7ccf6b04878e2d5f71ff11205 SHA-256: fe732822454a6903cedbb8c1b0d930a4229aa57f6d44407873b53183d37e9b2a
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a critical heuristic firing for a malicious redirector link pointing to 'https://ttraff.me/pify?keyword=what+is+martensite+formation'. Additionally, another critical heuristic indicates a PDF link farm, suggesting a broader campaign to distribute malicious content. The ML classifier strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains the same URL, reinforcing the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/pify?keyword=what+is+martensite+formation
    • https://static.usrfiles.com/ugd/d54300_087578098faf40fc837016cb42364e3f.pdf
    • https://static.usrfiles.com/ugd/f46427_1838ff50ea2542b5a3511710cb33dabc.pdf
    • https://static.usrfiles.com/ugd/0c4177_e710dfd51a034f54a704aae49dc2c59b.pdf
    • https://static.usrfiles.com/ugd/c8d394_c0da4824b71a4d258b0a2418e6eb6fec.pdf
    • https://static.usrfiles.com/ugd/07ef24_05f70c50e6bc4621851961de3292e61b.pdf
    • https://static.usrfiles.com/ugd/704988_74c5be96005e475e91925ddd153bd763.pdf
    • https://static.usrfiles.com/ugd/0baf77_9409dfd81398487f8a53d9d51fb3235e.pdf
    • https://cdn.shopify.com/s/files/1/0439/5030/9531/files/xem_phim_minority_report_vietsub.pdf
    • https://cdn.shopify.com/s/files/1/0430/3942/4669/files/27258140066.pdf
    • https://cdn.shopify.com/s/files/1/0431/2314/6909/files/litotiguvomiwada.pdf
    • https://cdn.shopify.com/s/files/1/0435/4090/6143/files/design_of_wood_structures_solutions_manual.pdf
    • https://cdn.shopify.com/s/files/1/0431/1898/5372/files/85659766865.pdf
    • https://cdn.shopify.com/s/files/1/0438/2972/3293/files/tcl_55s423_review.pdf
    • https://cdn.shopify.com/s/files/1/0433/6893/9672/files/cms_1500_form_template_free.pdf
    • https://cdn.shopify.com/s/files/1/0431/6083/0116/files/language_arts_worksheet_6th_grade.pdf
    • https://cdn.shopify.com/s/files/1/0433/2286/7880/files/mowujifesote.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000da58.bin
99059a10c2da60e6c817f67574087c508c0ef1f71f61490b485af1ad31d56fc1
pdf-font-stream PDF embedded font (sfnt) at offset 0xDA58 4988 bytes
font_01_sfnt_off0000eb2e.bin
a200c2995233127d0f70c3fa22ec308c9cf3e4a68f291f49f96d30cf90fd3531
pdf-font-stream PDF embedded font (sfnt) at offset 0xEB2E 15788 bytes