Malicious PDF — malware analysis report

Static analysis result for SHA-256 d0c2a52528cd7e8e…

MALICIOUS

PDF

35.4 KB Created: 2020-09-19 00:37:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b242989fce7003b620af879672c19d07 SHA-1: 157075bd8fcd085f455fc199ca45af4e998852c4 SHA-256: d0c2a52528cd7e8ee9cd27c853bf679ebfbecff2b2177474d01629836020a157
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, directing users to 'https://ttraff.me/wix?keyword=wake+county+math+3+released+tests'. Additionally, it exhibits characteristics of a PDF link farm, with numerous external links, some of which point to potentially malicious infrastructure. The ML classifier also strongly indicated maliciousness. No scripts were extracted, but the presence of multiple external links suggests a delivery mechanism for further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=wake+county+math+3+released+tests
    • http://lajipame.pacificallriskinsurancebrokers.com/uploads/1/3/1/4/131407995/6590561.pdf
    • http://lemekada.kpcouncil.org/uploads/1/3/1/4/131411341/f5e4748df0.pdf
    • https://1191fc5f-b6f1-4ebf-8972-53e328c065bf.filesusr.com/ugd/baa514_0f6892ae894441859947e4eeae68aa37.pdf?index=true
    • https://b2670b50-8a68-42b8-9ec7-9f586cad45b8.filesusr.com/ugd/11baf9_325b63edeb4a4c0a9d2157cbf18c867d.pdf?index=true
    • https://58d33326-fae6-495c-990f-d472fc317636.filesusr.com/ugd/e2c6c1_c2c8db4c2a76446cb02e2badbb3c7099.pdf?index=true
    • https://c2f02921-0dab-4f03-bc13-4cb5ec292a38.filesusr.com/ugd/b1277d_fad2cb71bf614886a14bb827307ba722.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0438/3971/7538/files/aparichithudu_movie_songs_320kbps.pdf
    • https://cdn.shopify.com/s/files/1/0431/3759/7607/files/26726517545.pdf
    • https://cdn.shopify.com/s/files/1/0431/4054/6714/files/30144927621.pdf
    • https://cdn.shopify.com/s/files/1/0430/0334/7097/files/2529478012.pdf
    • https://cdn.shopify.com/s/files/1/0480/0197/4425/files/basic_stoichiometry_phet_post_lab_answers.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004bbc.bin
96a74f96edbda8b7054f574547e433a7b180783583916e2cc743bdb38ac56629
pdf-font-stream PDF embedded font (sfnt) at offset 0x4BBC 5520 bytes
font_01_sfnt_off00005e6a.bin
7024e90e76120f8b5ced8428f8ebdbeb96d5f466b5c5d68b2b5235134d90dc91
pdf-font-stream PDF embedded font (sfnt) at offset 0x5E6A 10192 bytes