Malicious PDF — malware analysis report

Static analysis result for SHA-256 d85188e56c27b5ac…

MALICIOUS

PDF

42.4 KB Created: 2020-09-19 11:53:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 024d64289291213d59573acbbc398085 SHA-1: 96400a7beb4e88ea6126edeeaf28c358dee956b5 SHA-256: d85188e56c27b5acbcce48191ec588997622593a4705c6f744df4734fce938e7
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains multiple embedded links, with a critical heuristic firing for a malicious redirector. One prominent link directs to 'https://ttraff.club/wix?keyword=sps+school+calendar+2020', which is flagged as malicious. Another link, 'http://sogawe.xtremeie.com/uploads/1/3/1/0/131070678/7737569.pdf', is part of a large link farm, suggesting an attempt to distribute malicious content or engage in SEO manipulation for malicious purposes. The ML classifier also strongly indicates maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=sps+school+calendar+2020
    • http://sogawe.xtremeie.com/uploads/1/3/1/0/131070678/7737569.pdf
    • http://files.gomriz.com/uploads/1/3/1/4/131410685/wuveki.pdf
    • http://files.officeassetsreused.com/uploads/1/3/0/8/130874163/baperojuginegeralixo.pdf
    • http://files.cookiesthenmilk.com/uploads/1/3/1/4/131483371/4737943.pdf
    • https://cdn.shopify.com/s/files/1/0486/5379/5486/files/zygor_gold_guide.pdf
    • https://cdn.shopify.com/s/files/1/0432/7692/7141/files/citrus_deficiency_guide.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/43778875991.pdf
    • https://cdn.shopify.com/s/files/1/0435/8347/1771/files/59070889746.pdf
    • https://fc9d7037-f0a3-472b-864c-648dcf18e126.filesusr.com/ugd/a76634_9fe17097b5ab4152ac6df619ee32121a.pdf?index=true
    • https://c6a6f746-f5e3-4fcf-8457-e377abead931.filesusr.com/ugd/0010c8_f3940cfc7b0947d98234e1ce3577a5f9.pdf?index=true
    • https://0187f6a6-c53d-4518-a3b0-c8118953ac38.filesusr.com/ugd/ce4b7c_c6f13cbe6b3e4dce9cbade8f778005d2.pdf?index=true
    • https://d556ee9b-ff43-49ed-bcf5-546a991b6a3d.filesusr.com/ugd/d7ba0f_608e17cb8ed644e5924d65ee9944e382.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0440/6142/5814/files/41657334481.pdf
    • https://cdn.shopify.com/s/files/1/0436/5415/2342/files/reliance_general_insurance_annual_report_2018-_19.pdf
    • https://cdn.shopify.com/s/files/1/0462/7342/9661/files/blank_calendar_template_2019_july.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000066e9.bin
20270ca0473997523ad7bb85b3e39fccc4ccdab7dd0e5a7db80861f4e2e2ed18
pdf-font-stream PDF embedded font (sfnt) at offset 0x66E9 5540 bytes
font_01_sfnt_off000079b3.bin
6799828d666170c78fbe3b024528745e075b0576681511bc0a1792642785a8c2
pdf-font-stream PDF embedded font (sfnt) at offset 0x79B3 10312 bytes