Malicious PDF — malware analysis report

Static analysis result for SHA-256 b6db546d2223c0ad…

MALICIOUS

PDF

43.0 KB Created: 2020-09-17 10:47:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 02680617d5c17fa5a981f9e239d16a3a SHA-1: 60beac4b5437484f6f596df31779ba447da30fa8 SHA-256: b6db546d2223c0ad045484d609fe7a01653762f2bab4a957816abc7b50d6f003
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a significant number of embedded links, identified as a PDF link farm. One of these links directs to a known malicious redirector infrastructure. The document body, though heavily obfuscated, contains URLs that are consistent with this link farm behavior. The primary attack pattern involves leveraging these links for malicious purposes, potentially SEO manipulation or distributing further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=exponential+function+worksheet+kuta
    • http://files.snowstorm-artstudio.com/uploads/1/3/0/8/130873984/1874242a87ccff.pdf
    • http://files.alisonjassoc.com/uploads/1/3/0/8/130813931/650e76db.pdf
    • http://files.mi928.com/uploads/1/3/0/7/130776406/835183.pdf
    • http://vazuwixer.eluniteddivetravel.com/uploads/1/3/1/8/131857363/joranol_nofejup_pinufafixixu_kuwoso.pdf
    • https://99b71f00-24ad-420f-8b38-863735ad5781.filesusr.com/ugd/50de67_0101e514299741a5babff7a05d25769b.pdf?index=true
    • https://772ce74b-1199-436b-8f7f-0c4a7fdb5374.filesusr.com/ugd/61567a_a06f6ed745224860807a0a267ab978dc.pdf?index=true
    • https://f1c3a2f7-a9aa-48a4-9a76-baae6e41bcee.filesusr.com/ugd/d2751c_9e242dc7472b4843aa0954546b13d817.pdf?index=true
    • https://a3563421-6ef2-4d07-a964-4e86a5d986a8.filesusr.com/ugd/429b25_c849834cc2a14146adc79eba39c90664.pdf?index=true
    • https://f3e0c5ea-d6b4-4288-af3d-57876f54281e.filesusr.com/ugd/dcf311_a2a94dcdc56c4cc1bf455e9bae1ed296.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0428/7276/6631/files/56900863458.pdf
    • https://cdn.shopify.com/s/files/1/0432/9524/4441/files/vunirenarejigunudefote.pdf
    • https://2b2fdc7b-fd4c-45d1-86fc-d2a6a9a619c5.filesusr.com/ugd/33a16d_62bc7adeba1a4c4c967826344641d902.pdf?index=true
    • https://230034a8-0535-4825-a734-7fb1ba8bb298.filesusr.com/ugd/10cedf_59860edf78cf40eba0abe2b9fd439264.pdf?index=true
    • https://acee0fb9-ff88-4b5c-a8af-c71eb647ead5.filesusr.com/ugd/6203b9_e277537e72f84d168683aece7e1a4a9b.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005a3f.bin
2b684bb31666e24f7ce3fef68692624bdb1a0a0158547aad55675331c339fbfd
pdf-font-stream PDF embedded font (sfnt) at offset 0x5A3F 4116 bytes
font_01_sfnt_off0000695a.bin
fc6942aa3f39431b8c3d03bd393ebc2c129ee7a128d185965959e551a9c145b1
pdf-font-stream PDF embedded font (sfnt) at offset 0x695A 5284 bytes
font_02_sfnt_off00007b6c.bin
8373e95fb2ceae6a2d6af125f03a236e4d6853a315c93f592d71dde7119b0ee1
pdf-font-stream PDF embedded font (sfnt) at offset 0x7B6C 10304 bytes