Malicious PDF — malware analysis report

Static analysis result for SHA-256 b32f703f04f0cc3d…

MALICIOUS

PDF

34.4 KB Created: 2020-08-30 14:48:28 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 96df512893489b785d91fa6f26280f96 SHA-1: 50b716e6470738d3fd81e3b8b6c8e6f24302656c SHA-256: b32f703f04f0cc3d791aa73fa85612eb32e23a64df23298a2e2a06cd93077787
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a mass of external links, with the primary link directing to a known malicious redirector. The document body, though heavily obfuscated, contains the URL 'https://ttraff.com/wix?keyword=klein+organic+chemistry+solutions+manual+2nd+edition+pdf', which is flagged as malicious. This suggests the PDF is designed to lead users to malicious infrastructure, likely for further exploitation or phishing.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=klein+organic+chemistry+solutions+manual+2nd+edition+pdf
    • https://cdn.shopify.com/s/files/1/0431/5951/9387/files/beradinibe.pdf
    • https://cdn.shopify.com/s/files/1/0438/6373/6485/files/kureneninitive.pdf
    • https://cdn.shopify.com/s/files/1/0428/0621/4819/files/trafigura_interim_report_2019.pdf
    • https://cdn.shopify.com/s/files/1/0432/7328/9894/files/catholic_handbook_of_deliverance_prayers.pdf
    • https://static.usrfiles.com/ugd/930050_48d10e2a24424478a6f3a7f4ec5a8fb4.pdf
    • https://static.usrfiles.com/ugd/77941b_5e9fcc24ab8a4f2baef31e2cfd0416aa.pdf
    • https://static.usrfiles.com/ugd/158fb9_cb5ad3048ffd42c69f2cd383ee878323.pdf
    • https://static.usrfiles.com/ugd/dd4472_3cf6df89e7a542c1b4be1b6a669c0e69.pdf
    • https://static.usrfiles.com/ugd/d902bb_c027916b74a4453291f3eec010ae2858.pdf
    • https://static.usrfiles.com/ugd/469aea_bbf5240adf11424bb963a755767dd812.pdf
    • https://static.usrfiles.com/ugd/b8c837_3747a899bcf04340a272ee1d411db89a.pdf
    • https://static.usrfiles.com/ugd/0d2908_5a3a944683f44a6d9e05948f07be514d.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004690.bin
0746f086da9f99fe3aa4d8b22ed87b5a3be68448d8604f2629c52487bbf273c9
pdf-font-stream PDF embedded font (sfnt) at offset 0x4690 5772 bytes
font_01_sfnt_off00005a18.bin
a17f63cb02b6d808d2f3e1a07f0784bc7c59f5e63ffc4b6fe3f5780694c14b53
pdf-font-stream PDF embedded font (sfnt) at offset 0x5A18 10016 bytes