Malicious PDF — malware analysis report

Static analysis result for SHA-256 1cfe2cbfaa954bf3…

MALICIOUS

PDF

48.2 KB Created: 2020-08-30 07:29:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c1d6ce94dcf68e60e2eaeb209c23113a SHA-1: 3fa46d95a588f27848a84f3f9d6f7f1524140eb8 SHA-256: 1cfe2cbfaa954bf3f31ca2bee492c8f494a69e0102e65eeb49380d22f33f0dc4
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a heuristic firing for a malicious redirector link, which is also present in the document body. This link, 'https://ttraff.cc/wix?keyword=washtenaw+community+college+academic', is designed to redirect the user to malicious infrastructure. The PDF also contains a large number of external links, many hosted on Shopify, which is indicative of a link farm used for SEO poisoning or to obscure the final malicious destination. No scripts were extracted, and the document body is heavily obfuscated, but the presence of the malicious redirector is the primary indicator of compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=washtenaw+community+college+academic
    • https://cdn.shopify.com/s/files/1/0432/7846/7222/files/66725456859.pdf
    • https://cdn.shopify.com/s/files/1/0448/2859/0242/files/angelcare_ac1100_manual.pdf
    • https://cdn.shopify.com/s/files/1/0431/4189/0208/files/gidemesikixoserukuga.pdf
    • https://cdn.shopify.com/s/files/1/0429/1090/8572/files/schlage_keypad_locks_programming_guide_fe575.pdf
    • https://cdn.shopify.com/s/files/1/0431/5119/6315/files/best_3d_photo_editing_app.pdf
    • https://cdn.shopify.com/s/files/1/0434/7808/9878/files/vibapib.pdf
    • https://cdn.shopify.com/s/files/1/0428/2168/1315/files/21263941493.pdf
    • https://static.usrfiles.com/ugd/6846fe_7fc33fc8ca5b436ab5fe7a233f09787d.pdf
    • https://static.usrfiles.com/ugd/a107db_d73e84cceaff490cb09a29dff8267b76.pdf
    • https://static.usrfiles.com/ugd/b8c837_aaea98ca805a4118a92d760239612e5c.pdf
    • https://static.usrfiles.com/ugd/b5aed9_b64db5ee01d14842b8f894f265f3bbb0.pdf
    • https://cdn.shopify.com/s/files/1/0431/5247/4267/files/anemia_hemolitica_severa_en_perros.pdf
    • https://cdn.shopify.com/s/files/1/0431/3799/0813/files/dilevinux.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000651d.bin
c703752afea13ac0ad8fe6503667ae5ad198d5b1bc4100d7e612a841a8b9394c
pdf-font-stream PDF embedded font (sfnt) at offset 0x651D 5344 bytes
font_01_sfnt_off00007739.bin
3a4091bcbe89000b88a6bafe52e6bba59c209e443c95746a8ac85df74ce3b2d4
pdf-font-stream PDF embedded font (sfnt) at offset 0x7739 15204 bytes
font_02_sfnt_off0000a5df.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0xA5DF 4324 bytes