Malicious PDF — malware analysis report

Static analysis result for SHA-256 3e7bb66b5838e03a…

MALICIOUS

PDF

38.1 KB Created: 2020-08-22 09:22:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 972a6e3bd6cdf85713ea9ee71a6d2c0a SHA-1: 9c691081394163401ba2d6f13fc19be49e2b8297 SHA-256: 3e7bb66b5838e03aa7a773f94e1b8abc0d033426cc82af6635fcd95aa5ef7a12
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a mass external link farm, with a primary link pointing to a known malicious redirector. The document body, though heavily obfuscated, contains the same malicious URL. The ML classifier also flagged this PDF with high confidence. The primary intent appears to be redirecting the user to malicious infrastructure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=m%25E1%25BA%25B7t+n%25E1%25BA%25A1+fresh+snail+mask+sheet
    • http://dololuvur.shift-vibes.com/uploads/1/3/1/4/131412032/fapamapawaf-mufugilito.pdf
    • http://files.swlar.com/uploads/1/3/2/7/132710569/07666bf9519f3.pdf
    • http://files.haltapes.com/uploads/1/3/0/7/130775504/bopidipis-xeber-punolav.pdf
    • http://dirurorob.artartmargaretcameron.com/uploads/1/3/0/8/130874565/waxaro.pdf
    • https://cdn.shopify.com/s/files/1/0435/4647/6708/files/surareloti.pdf
    • https://cdn.shopify.com/s/files/1/0436/2744/6435/files/brew_install_node.pdf
    • https://cdn.shopify.com/s/files/1/0433/0147/0366/files/vimaneze.pdf
    • https://cdn.shopify.com/s/files/1/0434/3146/1016/files/balarama_mayavi_download.pdf
    • https://cdn.shopify.com/s/files/1/0427/8406/3654/files/90810502237.pdf
    • https://cdn.shopify.com/s/files/1/0433/4695/2351/files/definition_of_office_management.pdf
    • https://cdn.shopify.com/s/files/1/0434/8693/7253/files/ramizigafuvoladug.pdf
    • https://cdn.shopify.com/s/files/1/0454/2119/9516/files/ambasamudram_ambani_video_songs_hd.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000570f.bin
1e727e1d02176bd072395cf7edecb2bcfdf3e446c5451d9b35363dd4df98030f
pdf-font-stream PDF embedded font (sfnt) at offset 0x570F 5584 bytes
font_01_sfnt_off000068b0.bin
38967a796abada54bc22f7c6faf51e0cf5bffdb78943d34902b606d354c23ffb
pdf-font-stream PDF embedded font (sfnt) at offset 0x68B0 9764 bytes