Malicious PDF — malware analysis report

Static analysis result for SHA-256 243bce2e4a4accce…

MALICIOUS

PDF

46.8 KB Created: 2020-08-15 19:38:28 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bbcd30bea9cc33e9002da3472e867ec2 SHA-1: 54d85a73fd5bda06d10885e13ed8d5485d36535b SHA-256: 243bce2e4a4accce3f67836cb3312f3c7aaa85afe96ccbbe42d660f561b9ddef
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a prominent link that is presented as a download for an "engineering material book pdf". This link directs to a known malicious redirector, indicating a phishing or social engineering attempt. The PDF also contains a large number of other links, many hosted on Shopify, which is characteristic of SEO link farm abuse to obscure malicious activity. No scripts were extracted, but the primary attack vector is the malicious URL embedded within the document.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wb?keyword=engineering%20material%20book%20pdf%20download
    • http://files.designsbygiacomo.com/uploads/1/3/1/4/131437671/jarisuvamuxulij_madabejerora_tuwokupit_xiraponixutonub.pdf
    • http://files.immersiveaudio.co/uploads/1/3/0/7/130775462/lepufizigusexedage.pdf
    • http://files.fuzzyudder.com/uploads/1/3/2/7/132710797/3652436.pdf
    • http://files.braverthanthewaves.com/uploads/1/3/1/4/131453807/5359755.pdf
    • http://files.goodshepherdinoshkosh.com/uploads/1/3/1/4/131454143/vosewudozokulizudep.pdf
    • https://cdn.shopify.com/s/files/1/0437/2535/7210/files/jisamazu.pdf
    • https://cdn.shopify.com/s/files/1/0436/1686/2371/files/xelazasovuzanokimatil.pdf
    • https://cdn.shopify.com/s/files/1/0440/2269/4046/files/kakalupupopevirojemunu.pdf
    • https://cdn.shopify.com/s/files/1/0429/2496/6044/files/biozone_year_11.pdf
    • https://cdn.shopify.com/s/files/1/0427/4782/2236/files/1206488860.pdf
    • https://cdn.shopify.com/s/files/1/0441/3744/7576/files/77477244624.pdf
    • https://cdn.shopify.com/s/files/1/0428/2574/4540/files/vaporukok.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/xibirinadinabamagumib.pdf
    • https://cdn.shopify.com/s/files/1/0432/6152/6179/files/reactions_of_diazonium_salts.pdf
    • https://cdn.shopify.com/s/files/1/0438/4237/1741/files/gupinubopikevebelogugit.pdf
    • https://cdn.shopify.com/s/files/1/0431/4651/0504/files/xunofosigepimoresaxowije.pdf
    • https://cdn.shopify.com/s/files/1/0434/0557/4309/files/9354211960.pdf
    • https://cdn.shopify.com/s/files/1/0438/2805/2130/files/antecedentes_historicos_de_la_administracion.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006257.bin
3a63af723237249d8db4fac27132ffcb42fc5de439eeb7d96c4e58a4d0022b00
pdf-font-stream PDF embedded font (sfnt) at offset 0x6257 5436 bytes
font_01_sfnt_off000074c1.bin
2d35fe1b112251630f6c3e185fb4bf58c6327cea99f60afab3ca0473214b5b30
pdf-font-stream PDF embedded font (sfnt) at offset 0x74C1 2116 bytes
font_02_sfnt_off00007e8d.bin
d00b1aef5c8d9dfbb3cfb44da283e76c5050b86f73c1a04872b7e53552e11e12
pdf-font-stream PDF embedded font (sfnt) at offset 0x7E8D 14504 bytes