Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b0f5becc60d4e97…

MALICIOUS

PDF

58.2 KB Created: 2020-08-06 23:00:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c34ff27b78d07abc6ffbd4a4132918c1 SHA-1: 3683b40ef2ef568b52ccbb5e2b4f60e60b5ba06f SHA-256: 4b0f5becc60d4e9725a96c7a0df547c5ef45dc1ba5b4608c022bf7f813ebd74b
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of external links, many of which point to Shopify domains, but one critical link redirects to a known malicious domain. This suggests a link farm or SEO poisoning tactic to lure users to malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted, limiting the analysis of specific execution behaviors.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=lexique+anglais+fran%25C3%25A7ais+pdf
    • http://setasab.gobigt.com/uploads/1/3/1/8/131871699/vijifumajuxex.pdf
    • http://files.oregontruffleoil.com/uploads/1/3/1/6/131606127/e5d80cf21abec6.pdf
    • http://files.kelseyjenkinson.com/uploads/1/3/2/8/132814024/6146315.pdf
    • http://files.stjohnsofolean.com/uploads/1/3/1/4/131438523/likabinamomakijuvi.pdf
    • https://cdn.shopify.com/s/files/1/0431/7341/3032/files/49556479204.pdf
    • https://cdn.shopify.com/s/files/1/0433/3692/5342/files/xopikuvojobupokewowowu.pdf
    • https://cdn.shopify.com/s/files/1/0434/2792/2076/files/pozivudavasibufas.pdf
    • https://cdn.shopify.com/s/files/1/0431/4392/1820/files/54629422629.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/dazexirorojukulovamedifuv.pdf
    • https://cdn.shopify.com/s/files/1/0431/5276/9192/files/zalifitogexunowuna.pdf
    • https://cdn.shopify.com/s/files/1/0430/0328/1571/files/discord_markdown_text.pdf
    • https://cdn.shopify.com/s/files/1/0435/9408/8611/files/agricola_family_edition_rules.pdf
    • https://cdn.shopify.com/s/files/1/0435/3127/2351/files/sivitatusetiw.pdf
    • https://cdn.shopify.com/s/files/1/0431/5031/1579/files/capf_assistant_commandant_2020_notification.pdf
    • https://cdn.shopify.com/s/files/1/0431/5473/5264/files/english_to_spanish_dictionary_with_pronunciation.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009391.bin
c90de37c1c583a20ee10218518c008721111b3042fb2b9f5541c8a90ff2bf03c
pdf-font-stream PDF embedded font (sfnt) at offset 0x9391 5220 bytes
font_01_sfnt_off0000a554.bin
4047a87cf841b6d2534f1e35e182ca50d1ffd21c57a95ee61624f32c034440d1
pdf-font-stream PDF embedded font (sfnt) at offset 0xA554 12332 bytes
font_02_sfnt_off0000cba6.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0xCBA6 4324 bytes