Malicious PDF — malware analysis report

Static analysis result for SHA-256 2dc56176ce36c6e9…

MALICIOUS

PDF

58.8 KB Created: 2020-09-17 00:17:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0109d1dfa65db097389c7b75e99ff116 SHA-1: a89649b0cd73e9adac29b8561c6e3336068d0738 SHA-256: 2dc56176ce36c6e99df9b2ab07cd15f0befb12610566bc5aa923b911fe8d0d0f
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, many of which point to suspicious domains and are flagged as malicious redirectors. The ML classifier also strongly indicated maliciousness. The document body, though heavily obfuscated, contains URLs that are part of a link farm, suggesting an attempt to manipulate search engine results or redirect users to malicious content. The primary attack pattern involves using a link farm within a PDF to drive traffic to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=multiply+and+divide+integers+word+problems+worksheet+pdf
    • http://zozosaf.northcobbphotoclub.com/uploads/1/3/0/7/130774977/fubokak-kesilipudipid-wuweridepex-poloxovonasovi.pdf
    • http://files.jamesarmstrongdesign.com/uploads/1/3/1/6/131606396/5723510.pdf
    • http://mewon.theconservationhub.com/uploads/1/3/0/8/130814328/3443584.pdf
    • https://cdn.shopify.com/s/files/1/0461/7902/5059/files/ukrainian_carol_of_the_bells_sheet_music.pdf
    • https://cdn.shopify.com/s/files/1/0438/1035/7405/files/496421328.pdf
    • https://cdn.shopify.com/s/files/1/0441/1087/2728/files/always_on_sql_server.pdf
    • https://cdn.shopify.com/s/files/1/0432/0791/7729/files/podadora_de_pasto_manual_pretul.pdf
    • https://2e665acb-392f-4417-8346-21707f3e9e5f.filesusr.com/ugd/d2cc1f_ebada1a1ad74432db75d3d7111e36302.pdf?index=true
    • https://90037f7f-ebf7-4836-86c6-a3ecb75467d1.filesusr.com/ugd/891219_85303cb7b7174d169f7c62a62871282f.pdf?index=true
    • https://91bf7076-212a-4a58-9c49-a05828cb3feb.filesusr.com/ugd/4bb894_cd5ff454b08c4502bd52e439f85397a3.pdf?index=true
    • https://9b15107e-0e6a-4665-b0dc-57da0838c4ba.filesusr.com/ugd/61b8bf_9e479d82ff43431b860e48a132b46c9b.pdf?index=true
    • https://dd8ace19-4508-4976-8d5e-657535bf4200.filesusr.com/ugd/5de1df_f5a9713149d9441a8de4e101c4b3bcd7.pdf?index=true
    • https://c6ae513a-e1e7-4ddc-b037-8e520aa4ab8f.filesusr.com/ugd/8e66a5_b11310d88c344d5d84e82b9be0378d7f.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009acc.bin
dd7b880f1c6958317b71933e3175eb4154b1281d355b69180e4ce829e506ee21
pdf-font-stream PDF embedded font (sfnt) at offset 0x9ACC 2828 bytes
font_01_sfnt_off0000a4c6.bin
cb1c2f03f125f89d3921aab98d5286cdaa0d96fc79be2faa30fb763349cdbc35
pdf-font-stream PDF embedded font (sfnt) at offset 0xA4C6 5916 bytes
font_02_sfnt_off0000b8e4.bin
78c0f24a1d3c35f4f473a7199103798c032dfe19ba9de0589e6358808b279f75
pdf-font-stream PDF embedded font (sfnt) at offset 0xB8E4 10116 bytes