Malicious PDF — malware analysis report

Static analysis result for SHA-256 8de2cd2c9378052b…

MALICIOUS

PDF

58.4 KB Created: 2020-08-14 12:06:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b1b731fbee299f7208be48001f45c334 SHA-1: 6f053283b64c1058af9128eb6c4f2df03b27eeac SHA-256: 8de2cd2c9378052be2e5285c232d88b44c0c2fbbaadc12a8057e1fdecf2ad6bf
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a link farm and a specific redirector URL that is flagged as malicious. The document body, though heavily obfuscated, contains the text 'Workplace safety inspection sheet' and the malicious URL, suggesting a lure to trick users into clicking the link. The ML classifier also strongly indicated maliciousness. The primary malicious IOC is the redirector URL which likely leads to further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=workplace+safety+inspection+sheet
    • http://files.tmwolfpack.org/uploads/1/3/1/8/131871814/salatipiropuko.pdf
    • http://files.ablmembersarea.com/uploads/1/3/2/6/132682745/mefunuji-raxonokipawavif-vewin.pdf
    • http://tunox.carrotpatchkids.com/uploads/1/3/0/8/130814124/kilidagariz.pdf
    • https://cdn.shopify.com/s/files/1/0428/3236/3676/files/84965282155.pdf
    • https://cdn.shopify.com/s/files/1/0438/0511/4528/files/epidemiologia_de_la_diabetes_en_mexico.pdf
    • https://cdn.shopify.com/s/files/1/0431/7511/6960/files/51287473675.pdf
    • https://cdn.shopify.com/s/files/1/0432/8914/9608/files/19353664614.pdf
    • https://cdn.shopify.com/s/files/1/0440/8508/4310/files/10263056255.pdf
    • https://cdn.shopify.com/s/files/1/0435/7442/7809/files/bakikedavinutufobet.pdf
    • https://cdn.shopify.com/s/files/1/0437/7047/8746/files/tofufobizafunukotanivas.pdf
    • https://cdn.shopify.com/s/files/1/0432/8452/9310/files/manifudusovedine.pdf
    • https://cdn.shopify.com/s/files/1/0430/5348/2138/files/high_school_chemistry_textbook_prentice_hall.pdf
    • https://cdn.shopify.com/s/files/1/0428/9898/1030/files/59732073491.pdf
    • https://cdn.shopify.com/s/files/1/0432/6470/4662/files/super_mario_rpg_strategy_guide.pdf
    • https://cdn.shopify.com/s/files/1/0433/2378/5370/files/setting_up_a_discord_server.pdf
    • https://cdn.shopify.com/s/files/1/0428/1987/9068/files/telivakogiweboganodipipaj.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009b65.bin
59b9cb0b7a2de678e3e0ef620b0ac82b45c5ed8492bffcd479e2546e0af6810e
pdf-font-stream PDF embedded font (sfnt) at offset 0x9B65 5072 bytes
font_01_sfnt_off0000acaa.bin
2a9f6aa64119ccb94f29e5428306c067ed88707d1eb94f06ac0bfe3d5a998e88
pdf-font-stream PDF embedded font (sfnt) at offset 0xACAA 9888 bytes
font_02_sfnt_off0000ce60.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0xCE60 4324 bytes