Malicious PDF — malware analysis report

Static analysis result for SHA-256 46d911817a417d36…

MALICIOUS

PDF

52.8 KB Created: 2020-08-21 02:51:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b8e5f9669475df0659bc1a435257d59d SHA-1: 0113794dcb82f9a5352a517196b43ba73cc9effa SHA-256: 46d911817a417d36119fc3329c77a6d62aa0ba04cfe4a1297e8d81f299c58187
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, many pointing to Shopify domains, but one critical link directs to a known malicious redirector. The heuristic 'PDF_MALICIOUS_REDIRECTOR_LINK' confirms this, and 'PDF_SEO_LINK_FARM' indicates a pattern of mass external PDF linking. The ML classifier also strongly flagged this PDF as malicious. The primary attack vector appears to be luring users to malicious infrastructure via these links.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=answers+with+joe+patreon
    • http://lubekamu.shopwithtub.com/uploads/1/3/1/1/131163599/5019510.pdf
    • https://cdn.shopify.com/s/files/1/0440/0755/5222/files/pcv_mcv_mch_mchc_rdw_full_form.pdf
    • https://cdn.shopify.com/s/files/1/0437/0323/8811/files/70408685401.pdf
    • https://cdn.shopify.com/s/files/1/0431/3051/9716/files/folufot.pdf
    • https://cdn.shopify.com/s/files/1/0434/0904/7717/files/zekibakosib.pdf
    • https://cdn.shopify.com/s/files/1/0434/6016/5797/files/70214597175.pdf
    • https://cdn.shopify.com/s/files/1/0435/5247/3252/files/sbi_net_banking_forgot_password_application_form.pdf
    • https://cdn.shopify.com/s/files/1/0429/8443/9971/files/9355969084.pdf
    • https://cdn.shopify.com/s/files/1/0435/5974/7745/files/tarozijupejowojowe.pdf
    • https://cdn.shopify.com/s/files/1/0431/5670/1346/files/6673303004.pdf
    • https://cdn.shopify.com/s/files/1/0440/1479/6965/files/free_baptism_certificate_template_word.pdf
    • https://cdn.shopify.com/s/files/1/0440/8328/2070/files/bescherelle_descargar_gratis.pdf
    • https://cdn.shopify.com/s/files/1/0437/8856/6680/files/25456781734.pdf
    • https://cdn.shopify.com/s/files/1/0435/1960/6936/files/pinebidipunovuf.pdf
    • https://cdn.shopify.com/s/files/1/0437/0723/6503/files/are_you_human_too_ost_songs.pdf
    • https://cdn.shopify.com/s/files/1/0432/5310/4790/files/80896445670.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006c1e.bin
fcd5c678e7d9917e7bf7a1747f7b673c201f53bb2bb4a1b752bea05d7b1137b0
pdf-font-stream PDF embedded font (sfnt) at offset 0x6C1E 5032 bytes
font_01_sfnt_off00007d37.bin
2ff00deb42adb7f3121f296a4d511250de23dcd85ad670bb526830527fd9a17b
pdf-font-stream PDF embedded font (sfnt) at offset 0x7D37 3460 bytes
font_02_sfnt_off00008b71.bin
71be6e6a619b7b569a5225a04589cba4a59565fbcbe78eb3f2251690f7745490
pdf-font-stream PDF embedded font (sfnt) at offset 0x8B71 11076 bytes
font_03_sfnt_off0000b137.bin
354dce64f07f3d7acdf6a04edf763950ffbfec4edcbb4bfe17b65a83544077bb
pdf-font-stream PDF embedded font (sfnt) at offset 0xB137 16036 bytes