Malicious PDF — malware analysis report

Static analysis result for SHA-256 907cf584dfe776a2…

MALICIOUS

PDF

45.0 KB Created: 2020-09-16 02:46:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 020f183049995cf034fa72de00202f91 SHA-1: 0e4cb942b850bdf8749aea902b6d74cafb9512dc SHA-256: 907cf584dfe776a23ccb233a21423cb29de3cb71a7eb03410a54d8318948c373
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, as indicated by the PDF_SEO_LINK_FARM heuristic. One of these links, https://ttraff.cc/wb?keyword=nature%20trim%20garcinia, is flagged as a malicious redirector. The ML classifier also strongly indicated maliciousness. The document body contains garbled text but also includes the same suspicious URL and several other PDF links, reinforcing the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wb?keyword=nature%20trim%20garcinia
    • http://files.pfcmalta.org/uploads/1/3/1/3/131379719/33351293a26ca.pdf
    • http://files.rebeccaattia.com/uploads/1/3/1/6/131636927/tazalesipa.pdf
    • http://files.pennyormsbee.ca/uploads/1/3/1/6/131606758/kaxibedawegadoja.pdf
    • http://files.bedfordcarecenters.com/uploads/1/3/0/8/130873945/makugasuzesafe.pdf
    • http://tavulop.aicheucr.com/uploads/1/3/0/7/130740013/suxomabuk.pdf
    • https://static.usrfiles.com/ugd/b8c837_7939f6dd75bb4f98a9d5adffb1a465b1.pdf
    • https://static.usrfiles.com/ugd/28146e_1875ff510a7545be92138f1887d3565a.pdf
    • https://static.usrfiles.com/ugd/1ebe14_4c83361652dc4ca2b1f18949147bf5db.pdf
    • https://static.usrfiles.com/ugd/b88e3d_a8599e96a5f64fd2bb9adfbd3b0082ba.pdf
    • https://cdn.shopify.com/s/files/1/0433/5943/6968/files/sudazarezepux.pdf
    • https://cdn.shopify.com/s/files/1/0481/5447/6693/files/tozitujo.pdf
    • https://cdn.shopify.com/s/files/1/0455/3310/2245/files/free_printable_calendar_word_format.pdf
    • https://static.usrfiles.com/ugd/e4d7df_f6c8852968bd4f07b1aca8f781c9dd3d.pdf
    • https://static.usrfiles.com/ugd/1decf9_5beb6a250fa64d3d9d10ca2f9870c164.pdf
    • https://static.usrfiles.com/ugd/3e5d97_2ee0ba75e94f44a0b07f50773063ec30.pdf
    • https://static.usrfiles.com/ugd/b8c837_a96b52027037426995c4055e1696a306.pdf
    • https://static.usrfiles.com/ugd/d5415a_b4ba47ea40f74ded8938b5830144ee04.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006517.bin
5bcb877cefdad60888f03f684b0bb7cce38eedd5359b28c94293bc23bc84502a
pdf-font-stream PDF embedded font (sfnt) at offset 0x6517 4648 bytes
font_01_sfnt_off000074cc.bin
474415848cf7cfa332efcf11fb37c8c79267f9e810ff8dbe003d4015e1e4e350
pdf-font-stream PDF embedded font (sfnt) at offset 0x74CC 10652 bytes
font_02_sfnt_off00009932.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0x9932 4324 bytes