Malicious PDF — malware analysis report

Static analysis result for SHA-256 b6d65bb8f67331cd…

MALICIOUS

PDF

41.7 KB Created: 2020-09-02 06:02:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f773803be70c58e191e67494cd5ba9e1 SHA-1: 7d11e5c329d7a9d0523b9fac03d61886a83cc127 SHA-256: b6d65bb8f67331cd2642070cd05948692644da715e6e07ceb5b2d6024a234a07
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a link farm designed to redirect users to malicious infrastructure, specifically disguised as a search result for 'beautiful baby boy photo'. The ML classifier strongly indicated maliciousness, and the PDF structure includes numerous external links, many hosted on Shopify, likely for SEO manipulation to obscure the malicious redirector. The primary malicious IOC is the redirector URL.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=beautiful+baby+boy+photo
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/nazowexoratusitufunu.pdf
    • https://cdn.shopify.com/s/files/1/0437/3266/4481/files/the_underground_fat_loss_manual_resu.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/kevimofurerofujasopam.pdf
    • https://cdn.shopify.com/s/files/1/0429/6887/5157/files/brevet_reporte_reunion.pdf
    • https://cdn.shopify.com/s/files/1/0452/6243/8560/files/belaxewegowubupiru.pdf
    • https://static.usrfiles.com/ugd/e4a001_dcff922d9de84d069e7b875bd78f492a.pdf
    • https://cdn.shopify.com/s/files/1/0429/3266/6524/files/43965767279.pdf
    • https://cdn.shopify.com/s/files/1/0428/1267/0111/files/74465376558.pdf
    • https://cdn.shopify.com/s/files/1/0430/2359/7725/files/35333977211.pdf
    • https://static.usrfiles.com/ugd/cfbfd2_a9a8809213394abaadfce70beec1e2e3.pdf
    • https://static.usrfiles.com/ugd/eb6612_2265b27a85d749188ceb5394676c6258.pdf
    • https://static.usrfiles.com/ugd/e32576_d6801363667645afbb95125fc9a41508.pdf
    • https://static.usrfiles.com/ugd/f64db8_39463b26dd6142a88f086022df5bae00.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000065db.bin
e625b04d9edd3a0d54a7566a622fd5bfa6e085f78d9fab7d356668560a71f9c1
pdf-font-stream PDF embedded font (sfnt) at offset 0x65DB 5004 bytes
font_01_sfnt_off000076ee.bin
4f0527c707a7beefa2aff2468be486a71769fd305a00b2609562a3d642f23b7d
pdf-font-stream PDF embedded font (sfnt) at offset 0x76EE 10444 bytes