Malicious PDF — malware analysis report

Static analysis result for SHA-256 052c44efddec6353…

MALICIOUS

PDF

43.7 KB Created: 2020-10-16 19:42:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-15
MD5: 4c10a0c0c89656d604d3061c7eacfea7 SHA-1: 486bd625e548706fbe934134bc178fa4c1e7c43f SHA-256: 052c44efddec63539a503faddfb7eb87ff0989a3136bc346727e28e81ea1b321
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded links, many of which point to SEO-optimized PDF files hosted on Shopify and Strikingly. One of these links, https://cctraff.ru/strik?keyword=localiza%25C3%25A7%25C3%25A3o+de+acueducto+cerebral+e, is flagged as a malicious redirector. This suggests the document is part of a link farm or SEO poisoning campaign designed to drive traffic to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/strik?keyword=localiza%25C3%25A7%25C3%25A3o+de+acueducto+cerebral+e In PDF document text
    • https://naxesitigas.weebly.com/uploads/1/3/0/7/130740165/fogovesakujog.pdfIn PDF document text
    • https://lasajiboz.weebly.com/uploads/1/3/1/3/131379041/4019852.pdfIn PDF document text
    • https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/ratefunerod.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369928/normal_5f895261a4116.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4369671/normal_5f8858f71d378.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://cdn.shopify.com/s/files/1/0471/0678/5430/files/86880741143.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0501/6957/7637/files/14994645686.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0498/7686/1086/files/air_pollution_quiz_questions_and_answers.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0501/1400/3098/files/paxuvekev.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0482/8010/9218/files/sigmund_freud_psychoanalytic_theory.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0433/9505/5766/files/46418854861.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0498/0054/4418/files/mechanics_of_machinery.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a1180c77-2b84-4c78-9e68-2d23bd9d9c3c/65839685462.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0a12169d-249e-4013-9ab8-282025444d95/fotupidosafowe.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/49709cdf-2909-4f4d-a31a-d5599b1609e5/55308882793.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/267af7ff-a90c-4528-8304-ef81a2aa748d/melafajoreluwafarilopot.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/33175467-d7b4-4570-871a-053a9ca5ed2a/jomawigekerabusew.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c9b842b6-2fed-476b-90c7-7eb49e488aec/77216961136.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0ebd3f9d-691f-4be6-a382-6254d1c22ed1/zidorulasudiruxet.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000692e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x692E 5384 bytes
SHA-256: ef354043c1b9958c44322016c5316fda0aff7d9c54abfe1316e482e0dfb6659d
font_01_sfnt_off00007aa6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7AA6 12376 bytes
SHA-256: ea99189add13404f3574a16ace8b820e6c8d11e640cfd70626d621bf640bbd3d