Malicious PDF — malware analysis report

Static analysis result for SHA-256 c2eba7627c72d4c1…

MALICIOUS

PDF

40.5 KB Created: 2020-08-17 02:03:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b3e2ae2f38943992e36680a3a24b3d0e SHA-1: a6c35a405e9c97df51c5279913bae1f805827128 SHA-256: c2eba7627c72d4c17993f7b65447ffae4d25394cc1bc4f72cec069d60e79d558
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a significant number of embedded links, with one identified as a malicious redirector. The heuristic firings indicate a PDF link farm, suggesting the document's primary purpose is to distribute malicious links or manipulate search engine results. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=attur+weather+report+today
    • http://files.musictypographer.com/uploads/1/3/1/0/131070113/dopudeso-lamuxexazabafab-nalabodunubi.pdf
    • http://files.leedokyun.com/uploads/1/3/2/7/132712093/kakebe_sojiwag_kemuxaruno_wunafuwilegud.pdf
    • https://cdn.shopify.com/s/files/1/0435/5466/8705/files/nuboratamukak.pdf
    • https://cdn.shopify.com/s/files/1/0431/0443/6390/files/116405919.pdf
    • https://cdn.shopify.com/s/files/1/0428/3092/1895/files/bevotinapekipu.pdf
    • https://cdn.shopify.com/s/files/1/0439/3140/2395/files/prove_it_excel_2010_test_cheat_sheet.pdf
    • https://cdn.shopify.com/s/files/1/0440/6283/4853/files/sidamonogapabufukosixum.pdf
    • https://cdn.shopify.com/s/files/1/0437/6929/9098/files/21129055788.pdf
    • https://cdn.shopify.com/s/files/1/0430/7881/1797/files/67641826839.pdf
    • https://cdn.shopify.com/s/files/1/0430/7946/7170/files/46635503548.pdf
    • https://cdn.shopify.com/s/files/1/0435/3087/9136/files/big_bang_theory_essay.pdf
    • https://cdn.shopify.com/s/files/1/0432/6424/5925/files/28488060360.pdf
    • https://cdn.shopify.com/s/files/1/0434/5580/7641/files/antinutrients_in_legumes.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000057eb.bin
532c1a1cc4323b8cf5ce818c942a60329246ef7b1ad473840a82411df7617047
pdf-font-stream PDF embedded font (sfnt) at offset 0x57EB 5020 bytes
font_01_sfnt_off0000690d.bin
df28ebc2b862636896b1c840a5b84af466daf01373fcece57a54320da97f39ac
pdf-font-stream PDF embedded font (sfnt) at offset 0x690D 14256 bytes