Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b8b7675efef3ef4…

MALICIOUS

PDF

41.9 KB Created: 2020-08-15 08:44:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ad4a67c890418594852c818c0e6a89bb SHA-1: bc87842707f3279c8200447aaaeb5edfb0327bd5 SHA-256: 4b8b7675efef3ef48c280d80122f6c7356edeefb5e215fc73824d5826b11531d
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a high number of embedded links, many pointing to Shopify domains, but one critical link directs to a known malicious redirector. The document body, though heavily obfuscated, contains the URL that triggers the malicious redirector. This suggests a phishing or scam attempt using a link farm to obscure the final malicious destination.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=bootstrap+4+checkout+page+template
    • http://files.reflectionssalonmthoreb.com/uploads/1/3/1/3/131383837/dutirojifarabi.pdf
    • http://files.brownassociatesinsurance.com/uploads/1/3/1/4/131454620/julole.pdf
    • http://files.priorityoneinc.com/uploads/1/3/0/8/130813526/dikoxupumiji.pdf
    • http://files.gethealthyinitiative.org/uploads/1/3/2/7/132740637/5880898.pdf
    • http://files.maureenriley.org/uploads/1/3/1/3/131380482/5032064.pdf
    • https://bbbootstrap.com/snippets/embed/checkout-form-12016070-name/BBBootstrap
    • https://cdn.shopify.com/s/files/1/0432/1896/0545/files/working_principle_of_autoclave_machine.pdf
    • https://cdn.shopify.com/s/files/1/0433/3741/6869/files/dolabusof.pdf
    • https://cdn.shopify.com/s/files/1/0438/6711/1584/files/96406602884.pdf
    • https://cdn.shopify.com/s/files/1/0434/8909/9938/files/jurijuziwomisuxu.pdf
    • https://cdn.shopify.com/s/files/1/0432/3573/7755/files/modern_automotive_technology_9th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0430/7389/6602/files/78305016759.pdf
    • https://cdn.shopify.com/s/files/1/0435/4696/8218/files/83658022013.pdf
    • https://cdn.shopify.com/s/files/1/0443/8245/3926/files/performance_appraisal_journal.pdf
    • https://cdn.shopify.com/s/files/1/0439/7305/0526/files/86951047704.pdf
    • https://cdn.shopify.com/s/files/1/0434/6327/8758/files/xuxubozivaliwotojabe.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005780.bin
ef18acf32490260be070e015709ebd9692d3b9fa086e4a3f1d6faabaff7d892d
pdf-font-stream PDF embedded font (sfnt) at offset 0x5780 5548 bytes
font_01_sfnt_off00006a45.bin
cc4d78c83103c3c8d3329365aab7893ff5d1320b475ad2d74d05348350a8dff9
pdf-font-stream PDF embedded font (sfnt) at offset 0x6A45 15400 bytes