Malicious PDF — malware analysis report

Static analysis result for SHA-256 cca52e16740cba4a…

MALICIOUS

PDF

33.1 KB Created: 2020-10-19 01:20:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 79dd460545b271ae7ea966dfe215f24e SHA-1: e38e5eddfe37bc43e53506b10ad7a136dc508aa2 SHA-256: cca52e16740cba4aca3dd0fd3bb924749ee8a1cd3be7ca51dc3378d0eac626c5
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a mass of external links, with one prominent link pointing to a known malicious redirector. The document body, though heavily obfuscated, contains the URL 'https://cctraff.ru/strik?keyword=royal+pains+torrent', suggesting a lure for torrent downloads. This indicates the PDF is likely used for phishing or distributing further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9990

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/strik?keyword=royal+pains+torrent
    • https://cdn-cms.f-static.net/uploads/4370528/normal_5f8a0352cb380.pdf
    • https://cdn-cms.f-static.net/uploads/4367674/normal_5f8778be2522f.pdf
    • https://cdn-cms.f-static.net/uploads/4366987/normal_5f874a5f3369f.pdf
    • https://cdn-cms.f-static.net/uploads/4369629/normal_5f8ca5b758332.pdf
    • https://cdn-cms.f-static.net/uploads/4368953/normal_5f88950b42861.pdf
    • https://cdn-cms.f-static.net/uploads/4375518/normal_5f8b0c796d1c1.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/ac10abd0-a33f-43d9-befe-8a599e98df65/99450144524.pdf
    • https://uploads.strikinglycdn.com/files/579d1b8f-2d78-4fce-ba22-21566ed2004b/womevodulusupivotesiwu.pdf
    • https://uploads.strikinglycdn.com/files/341b3b21-903c-4c90-840b-6636d27750a6/xadamejobigokodojopa.pdf
    • https://cdn.shopify.com/s/files/1/0481/3337/4119/files/denver_school_of_the_arts_jobs.pdf
    • https://cdn.shopify.com/s/files/1/0483/5701/5701/files/14123201678.pdf
    • https://cdn.shopify.com/s/files/1/0479/7248/3228/files/33180725914.pdf
    • https://cdn.shopify.com/s/files/1/0428/3754/1031/files/estudio_de_capacidad.pdf
    • https://cdn.shopify.com/s/files/1/0497/0912/1715/files/32216382067.pdf
    • https://cdn.shopify.com/s/files/1/0431/9277/8916/files/71289766776.pdf
    • https://cdn.shopify.com/s/files/1/0432/0106/9220/files/29216712757.pdf
    • https://cdn.shopify.com/s/files/1/0502/9661/9193/files/dispositivos_de_almacenamiento_primario.pdf
    • https://cdn.shopify.com/s/files/1/0482/5631/9642/files/the_earth_norman.pdf
    • https://cdn.shopify.com/s/files/1/0437/8211/1390/files/navy_captain_assignments.pdf
    • https://cdn.shopify.com/s/files/1/0486/2630/3134/files/void_configuration_destiny_2.pdf
    • http://scripts.sil.org/OFL

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005374.bin
e492ca476c64fec3352ff2146bdd08df5e4492ba611773920d79a36df5c26441
pdf-font-stream PDF embedded font (sfnt) at offset 0x5374 4924 bytes