Malicious PDF — malware analysis report

Static analysis result for SHA-256 7c6cf06cd8e5cfea…

MALICIOUS

PDF

114.1 KB Created: 2020-07-26 07:09:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0173c77054145dc4cbcbc98ca533d33c SHA-1: 21fb42a47ae489a849d2a95b39b9f2bb83ed162c SHA-256: 7c6cf06cd8e5cfea0d64233bd842ee8959802f3620d15a918fe5b41f54a70217
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a malicious redirector link disguised as training material. The ML classifier strongly indicates maliciousness. The primary IOC is the redirector URL, which is designed to lead users to further malicious content. The PDF also hosts a large number of other PDF links, likely for SEO manipulation or to spread the malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=lean+six+sigma+black+belt+training+pdf
    • http://files.ren-ito.com/uploads/1/3/1/4/131483110/d686905359d71.pdf
    • http://files.kristina-mazeikaite.com/uploads/1/3/0/7/130775231/6753322.pdf
    • http://files.cardiologycarolina.com/uploads/1/3/0/7/130739069/6441498.pdf
    • http://files.bigskywords.com/uploads/1/3/0/8/130813841/0999726961470.pdf
    • https://cdn.shopify.com/s/files/1/0432/1217/7572/files/fibulazo.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/95509007145.pdf
    • https://cdn.shopify.com/s/files/1/0428/7981/1750/files/64667291573.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/68736518606.pdf
    • https://cdn.shopify.com/s/files/1/0431/7088/9892/files/19501210309.pdf
    • https://cdn.shopify.com/s/files/1/0435/3789/1477/files/dumekavinafuded.pdf
    • https://cdn.shopify.com/s/files/1/0429/8863/4263/files/69926707646.pdf
    • https://cdn.shopify.com/s/files/1/0432/6224/7080/files/79366676475.pdf
    • https://cdn.shopify.com/s/files/1/0431/9356/5342/files/suwisokexajobaneveg.pdf
    • https://cdn.shopify.com/s/files/1/0432/6676/9054/files/filonokifefoviwevan.pdf
    • https://cdn.shopify.com/s/files/1/0430/0426/4602/files/lugowobitowu.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/54183348773.pdf
    • https://cdn.shopify.com/s/files/1/0435/1095/6196/files/64396447222.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001677b.bin
e5ddcf87b984228bd2484228f52ed603eb1c939ce2f9c70404d77728b37e2272
pdf-font-stream PDF embedded font (sfnt) at offset 0x1677B 5368 bytes
font_01_sfnt_off0001799e.bin
441c6d6725c37e72a93c46ff2114f7716cb721004d5e0378280fe9471dd5f13c
pdf-font-stream PDF embedded font (sfnt) at offset 0x1799E 13724 bytes
font_02_sfnt_off0001a5b7.bin
713933360072c9d59346590fad668f98c3603c6d2b72ed941ce85481f6af0b74
pdf-font-stream PDF embedded font (sfnt) at offset 0x1A5B7 16060 bytes