Malicious PDF — malware analysis report

Static analysis result for SHA-256 b773c056aab3cd99…

MALICIOUS

PDF

32.1 KB Created: 2020-09-08 03:53:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 050b3e0cfddf90196b8ec51c8f08a8de SHA-1: 651b22152d3f892c798be4e03cf13df10e56d15e SHA-256: b773c056aab3cd9984036fa0e934c7e14f27838e3405964e056ec683c961f200
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, with one identified as a malicious redirector. The ML classifier also flagged this PDF as malicious. The primary attack pattern involves redirecting users to potentially harmful sites, likely for phishing or malware delivery. No scripts were extracted, limiting the analysis of specific execution behaviors.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=hindu+god+pictures
    • https://static.usrfiles.com/ugd/1da05d_593fcebebc6d41b29190dc895bf4525b.pdf
    • https://static.usrfiles.com/ugd/c57cae_7093c8d7e04348af93d9570b7ad26d09.pdf
    • https://static.usrfiles.com/ugd/98d33d_aa6ef878c7e042d3890311fba7ad686e.pdf
    • https://static.usrfiles.com/ugd/edb4a7_d8d5ba487f0f448ea5b60b77f9bf9d7e.pdf
    • https://cdn.shopify.com/s/files/1/0434/7022/5558/files/chemistry_class_11_ncert.pdf
    • https://cdn.shopify.com/s/files/1/0437/2863/4010/files/zapilapadogulafusod.pdf
    • https://cdn.shopify.com/s/files/1/0462/4246/3898/files/elianto_essence_mask_sheet_review.pdf
    • https://cdn.shopify.com/s/files/1/0436/1283/1907/files/sorting_algorithms_in_c.pdf
    • https://static.usrfiles.com/ugd/2f3216_93dfe26c4c7847568d4d7adf37065ffe.pdf
    • https://static.usrfiles.com/ugd/e2b09b_caa9c3ef7dfa4feab2f25b0aaffacfb6.pdf
    • https://static.usrfiles.com/ugd/1849a1_b545cf2ba6864cb9b4b0f09bfc72a760.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000042a5.bin
fa7441b22e39719549962f32044827fde485c0dd56c0a30ff47cf0673f009fa5
pdf-font-stream PDF embedded font (sfnt) at offset 0x42A5 4960 bytes
font_01_sfnt_off0000539c.bin
16398d453a2b18f962de201a3bf5f84a3ff935f4cad77eff36250495ca30550d
pdf-font-stream PDF embedded font (sfnt) at offset 0x539C 9600 bytes