Malicious PDF — malware analysis report

Static analysis result for SHA-256 bb8d03d906b34c01…

MALICIOUS

PDF

45.3 KB Created: 2020-07-27 08:50:58 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a2f8a24ff84dcd1a9b8b521ee97cb401 SHA-1: de14ece59a33dac3f4e0cf03260daa97310f4226 SHA-256: bb8d03d906b34c01e5cbc5cfa698fe721425ddcf85f208471120e102c1ba5adc
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified as a PDF link farm. One of the primary links directs to a known malicious redirector. The document body, though heavily obfuscated, contains text related to 'Twitter icon png for android', suggesting a lure to attract clicks. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=twitter+icon+png+for+android
    • http://files.dawnsbodyshop.com/uploads/1/3/0/7/130739509/tapokuzaxigi.pdf
    • http://files.cherrycanyondairy.com/uploads/1/3/0/7/130776655/7814208.pdf
    • http://files.theeagleempire.net/uploads/1/3/1/4/131437953/zusafujesetugijiludi.pdf
    • http://files.shotwellsharkband.com/uploads/1/3/2/6/132681336/rekutetawegu.pdf
    • https://cdn.shopify.com/s/files/1/0430/5109/0077/files/41713827695.pdf
    • https://cdn.shopify.com/s/files/1/0428/2250/0518/files/vokunebakojodefilusasef.pdf
    • https://cdn.shopify.com/s/files/1/0433/1952/5531/files/mabum.pdf
    • https://cdn.shopify.com/s/files/1/0431/3264/9636/files/45083924395.pdf
    • https://cdn.shopify.com/s/files/1/0432/9875/0629/files/vutigotured.pdf
    • https://cdn.shopify.com/s/files/1/0432/3042/9346/files/sakukavupir.pdf
    • https://cdn.shopify.com/s/files/1/0430/7920/5031/files/26735333032.pdf
    • https://cdn.shopify.com/s/files/1/0432/7846/7222/files/mefivi.pdf
    • https://cdn.shopify.com/s/files/1/0432/9386/8187/files/64233299583.pdf
    • https://cdn.shopify.com/s/files/1/0430/5325/2757/files/88421868215.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/bodadajigewodozisidezufe.pdf
    • https://cdn.shopify.com/s/files/1/0433/7834/4085/files/38793975592.pdf
    • https://cdn.shopify.com/s/files/1/0435/5666/7551/files/xexet.pdf
    • https://cdn.shopify.com/s/files/1/0432/6513/0660/files/76151235640.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007380.bin
7a2d69d4cc7c6f67d72e01b9b0d7d406109f41496987aef1f3a274501b6f4f6f
pdf-font-stream PDF embedded font (sfnt) at offset 0x7380 4944 bytes
font_01_sfnt_off00008468.bin
de968143d013ff0625c3f1045a5ed485d259c5106598b93f1b8fbc1433d96f37
pdf-font-stream PDF embedded font (sfnt) at offset 0x8468 10328 bytes