Malicious PDF — malware analysis report

Static analysis result for SHA-256 37e7f5336af026c7…

MALICIOUS

PDF

41.3 KB Created: 2020-08-30 20:10:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: acd388ec58d1a8f77c3647aa961f1664 SHA-1: 253f618d3b670dad68d4b5664e23d76d8259c15e SHA-256: 37e7f5336af026c7e1022088f1ff5b7774a788d3a129b518a96c91dfb1e62a3b
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link farm designed to appear as legitimate documentation, but ultimately redirects to a malicious URL. The primary malicious IOC is the redirector URL, which is used to obscure the final destination. The document body, though heavily corrupted, contains the malicious URL and references to troubleshooting an Android TV box remote, likely as a lure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=mygica+android+tv+box+remote+not+working
    • https://cdn.shopify.com/s/files/1/0438/5135/0166/files/3252974554.pdf
    • https://cdn.shopify.com/s/files/1/0434/1186/5751/files/fluval_306_manual.pdf
    • https://cdn.shopify.com/s/files/1/0432/3475/4728/files/2663635550.pdf
    • https://cdn.shopify.com/s/files/1/0428/5104/1447/files/vofusememofoz.pdf
    • https://cdn.shopify.com/s/files/1/0437/5805/9671/files/apc_back-_ups_xs_1300_manual.pdf
    • https://static.usrfiles.com/ugd/b8c837_ad796a46abf149ef8058e49501923ca8.pdf
    • https://cdn.shopify.com/s/files/1/0432/0083/9842/files/81663150378.pdf
    • https://cdn.shopify.com/s/files/1/0434/1045/6726/files/wimajinokomi.pdf
    • https://cdn.shopify.com/s/files/1/0427/7446/2631/files/wedumarobovapalutedafi.pdf
    • https://cdn.shopify.com/s/files/1/0432/0781/9422/files/34538737795.pdf
    • https://cdn.shopify.com/s/files/1/0428/1712/6563/files/47534808281.pdf
    • https://cdn.shopify.com/s/files/1/0430/6203/4589/files/todefolonud.pdf
    • https://cdn.shopify.com/s/files/1/0432/4517/4939/files/pagajijawadugimedesabelis.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006294.bin
805db95bad0797a207e72fcaa10b05184bbbbf780b0f61600c0aa0da8a93eed6
pdf-font-stream PDF embedded font (sfnt) at offset 0x6294 5580 bytes
font_01_sfnt_off000075a0.bin
6252163b9dcf9049930c08d09f7ac3f22cd40f2482221d639bced1acde267fd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x75A0 10196 bytes