Malicious PDF — malware analysis report

Static analysis result for SHA-256 b7accbc62563b5cd…

MALICIOUS

PDF

40.3 KB Created: 2020-08-29 18:53:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 043e8e0bcde2acad1ddea68d3f48ff5b SHA-1: 1cfa6d558bf3cd2d96fd6cdec5bfee7cf2c1c9aa SHA-256: b7accbc62563b5cd2a46ef43af422ed742092330b728203f76943cbd8c374fe3
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains numerous links, with one pointing to a known malicious redirector. The document body, though partially corrupted, includes text related to educational materials and the authoring application, suggesting a lure. The primary malicious IOC is the redirector URL, which likely leads to further malicious content or phishing attempts.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=cuadernillo+de+escritura+para+primer+grado+pdf
    • https://cdn.shopify.com/s/files/1/0433/9476/0862/files/90912244295.pdf
    • https://cdn.shopify.com/s/files/1/0432/8043/3302/files/pdf_to_word_converter_software_for_windows_10.pdf
    • https://cdn.shopify.com/s/files/1/0437/5438/9665/files/30495705779.pdf
    • https://static.usrfiles.com/ugd/d01287_83905370c22942b683054feaa7031818.pdf
    • https://static.usrfiles.com/ugd/b8c837_29cc4f099a0f4d629efbc9cdbdbc87e2.pdf
    • https://static.usrfiles.com/ugd/b8c837_ec97949417784b42addb4dcfc33af21e.pdf
    • https://static.usrfiles.com/ugd/b8c837_a4b6fcb9482148aca3017c43442dd105.pdf
    • https://static.usrfiles.com/ugd/921909_4a1b36700fc14b1ca85a00b417787237.pdf
    • https://static.usrfiles.com/ugd/b8c837_988bedc97cdb49f8883d70279d691a8f.pdf
    • https://static.usrfiles.com/ugd/b8c837_54acd1b4359e40bab030e4b644c34145.pdf
    • https://static.usrfiles.com/ugd/b8c837_fe8aeb1f89ed49f4afa2aec51ad6f582.pdf
    • https://static.usrfiles.com/ugd/b8c837_838b1f6d921a45f588b90eeb6c1afaef.pdf
    • https://static.usrfiles.com/ugd/b8c837_81b48788db024d088584af02255238f5.pdf
    • https://static.usrfiles.com/ugd/fe83c3_d46fa9009a9b4b4e88969a438943f45a.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005bb7.bin
5c4258baf0abd5e330df3bc62084a90d6f65e1908e5f03aa326f3d3203c686e5
pdf-font-stream PDF embedded font (sfnt) at offset 0x5BB7 5380 bytes
font_01_sfnt_off00006dea.bin
40a522a98cc6dfb1ac45ad3d94f91bd756765153be192324bdfaee9e1271ad37
pdf-font-stream PDF embedded font (sfnt) at offset 0x6DEA 11280 bytes