Malicious PDF — malware analysis report

Static analysis result for SHA-256 c632ced3dafa4a87…

MALICIOUS

PDF

36.7 KB Created: 2020-08-12 17:39:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b9acbf65235d325ffc879c47d80a6063 SHA-1: bae0882e401a4e01ba1693b85b6ea4bc878154b8 SHA-256: c632ced3dafa4a8762379e8236229f966e29591e6b12e279744cb4208e247859
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=arterial+blood+gas+interpretation+a+case+study+approach+pdf'. This indicates the document's primary purpose is to redirect users to malicious infrastructure. The presence of a large number of external PDF links, many hosted on Shopify, suggests a link farm SEO tactic to improve search engine ranking for malicious content. No scripts were extracted from this sample, but the embedded URLs and redirector link are sufficient to determine the attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=arterial+blood+gas+interpretation+a+case+study+approach+pdf
    • http://nenefut.hansenrestoration.com/uploads/1/3/1/4/131483144/marexaxakenebokodom.pdf
    • http://zamen.mingzhixu.com/uploads/1/3/1/4/131482853/6116607.pdf
    • http://files.cthorwigs.com/uploads/1/3/0/8/130814586/9029941.pdf
    • http://sifeluvi.crystalobregon.net/uploads/1/3/1/4/131482995/5661a3.pdf
    • http://files.michiganmidwife.com/uploads/1/3/1/4/131483719/b46bac00f.pdf
    • https://cdn.shopify.com/s/files/1/0436/2534/9283/files/94913018788.pdf
    • https://cdn.shopify.com/s/files/1/0434/6524/4832/files/xubizobafuwewuzeweviwok.pdf
    • https://cdn.shopify.com/s/files/1/0450/3588/0598/files/aditya_hrudayam_telugu_format.pdf
    • https://cdn.shopify.com/s/files/1/0435/4742/6975/files/pedialyte_nutrition_label.pdf
    • https://cdn.shopify.com/s/files/1/0449/8112/5278/files/lovetogodi.pdf
    • https://cdn.shopify.com/s/files/1/0432/3573/7755/files/avl_tree_java.pdf
    • https://cdn.shopify.com/s/files/1/0431/4886/9789/files/slope_of_parallel_and_perpendicular_lines.pdf
    • https://cdn.shopify.com/s/files/1/0428/5346/6271/files/80631861467.pdf
    • https://cdn.shopify.com/s/files/1/0431/5460/4198/files/44785186380.pdf
    • https://cdn.shopify.com/s/files/1/0450/2428/0726/files/kindred_graphic_novel_free.pdf
    • https://cdn.shopify.com/s/files/1/0430/9755/5108/files/levidi.pdf
    • https://cdn.shopify.com/s/files/1/0433/4246/3126/files/internal_audit_plan_template.pdf
    • https://cdn.shopify.com/s/files/1/0435/6656/3487/files/nigarofutijevonavanelis.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005120.bin
32847c2e23aa92c1ec5577bed8a5442745150f454af7edca208ac81ceb0edb57
pdf-font-stream PDF embedded font (sfnt) at offset 0x5120 5648 bytes
font_01_sfnt_off0000644d.bin
7944a738b9e2857129d178b2bbadc2ea36dbbee754ceadb9267d41315c1ae606
pdf-font-stream PDF embedded font (sfnt) at offset 0x644D 9748 bytes