Malicious PDF — malware analysis report

Static analysis result for SHA-256 2c2530772222d488…

MALICIOUS

PDF

56.4 KB Created: 2020-08-31 11:58:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: aca857e9ede528d5b8f3c1c3df77bf61 SHA-1: 21244e900d39cf1679e5440858e4436cdaa73dc0 SHA-256: 2c2530772222d488ef4fd7b9a490a072647eda39b688fbcf5eafa26d84ad0cc5
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a significant number of embedded links, with one identified as a malicious redirector. The document body, though heavily obfuscated, contains references to software names and URLs, suggesting a lure. The heuristic firings confirm the presence of a malicious redirector and a large link farm within the PDF, indicating an attempt to drive traffic to potentially harmful sites. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=foxit+phantompdf+free
    • https://static.usrfiles.com/ugd/b8c837_93241c886a3e4ff28d10ec4dead6cf3e.pdf
    • https://static.usrfiles.com/ugd/87a178_339c392079c640698db36f0bd85ff69e.pdf
    • https://static.usrfiles.com/ugd/1f6d71_afa4c2c1f0874d528d3328053e838433.pdf
    • https://static.usrfiles.com/ugd/b8c837_edda605b7c2e48e6832091829f7ad355.pdf
    • https://static.usrfiles.com/ugd/b8c837_51a779df1f9348c3967d9a86dfea61fc.pdf
    • https://static.usrfiles.com/ugd/b8c837_4d0dcc6942254291ad08b1dd63b43c85.pdf
    • https://static.usrfiles.com/ugd/b8c837_6856c0cdcb6f437490f3127a4ce77cb9.pdf
    • https://static.usrfiles.com/ugd/affb4a_ace6c03426b84bf28b050d5d1541bc09.pdf
    • https://static.usrfiles.com/ugd/defcb2_da2e42765ec24a90a0e5d8f1fdc669ae.pdf
    • https://static.usrfiles.com/ugd/7598fa_826a381683e24ebc9c5fde853e70d280.pdf
    • https://static.usrfiles.com/ugd/73cb9e_883b647e97384236ab01bd14c7301868.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/tufajotojitumawudawemir.pdf
    • https://cdn.shopify.com/s/files/1/0438/0560/6049/files/python_string_format_named_arguments.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/58580374151.pdf
    • https://cdn.shopify.com/s/files/1/0430/1848/5923/files/23761275108.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off0000a220.bin
a59adf94c644faf8e52e81e9e2e1d082295aa18dfd1f9ad4ae4630b56b4815f6
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xA220 28244 bytes
font_00_sfnt_off00006e1f.bin
73a204e38007c895f21a7dcfed527c54522ad743dad058ff766285321c742f48
pdf-font-stream PDF embedded font (sfnt) at offset 0x6E1F 5096 bytes
font_01_sfnt_off00007f46.bin
a27cfee93495078ef3fd0244bd5c77d74eed770d2fa5c9048900a3509b35477b
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F46 10080 bytes