Malicious PDF — malware analysis report

Static analysis result for SHA-256 e051cbbde5c759cf…

MALICIOUS

PDF

61.6 KB Created: 2020-09-16 16:51:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 01ae7a0a4f6074e7fd969a21de000998 SHA-1: 077a0d755d8ab742fdb9d3d72e5937b76c677eae SHA-256: e051cbbde5c759cfb03b33c33a1c918f20e4cf19e4745ba9482a37eb7a8e8802
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://ttraff.cc/wix?keyword=kelsey+o%2527connor+crown+castle'. Additionally, it exhibits characteristics of a PDF link farm, with numerous external links, many hosted on Shopify. The ML classifier also strongly flagged this PDF as malicious. The embedded document body text contains garbled data but also includes the primary malicious URL and several benign-looking Shopify URLs, suggesting a lure to disguise the malicious redirect.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=kelsey+o%2527connor+crown+castle
    • http://muwalov.mendingheartsrescue.org/uploads/1/3/0/8/130814423/dexofozarowajewaka.pdf
    • http://fuzopovo.warriorsfastpitch.com/uploads/1/3/1/3/131380344/22c6cf.pdf
    • http://wosavoxaz.conversationcompass.com/uploads/1/3/1/6/131606457/ruwenamo_lufifage_ziropopil.pdf
    • https://cdn.shopify.com/s/files/1/0436/3013/3408/files/quaternary_structure_of_proteins_information.pdf
    • https://cdn.shopify.com/s/files/1/0432/9209/8724/files/23778762390.pdf
    • https://cdn.shopify.com/s/files/1/0434/1704/3101/files/34494877391.pdf
    • https://cdn.shopify.com/s/files/1/0438/3073/9106/files/riwurukalewujowegez.pdf
    • https://cdn.shopify.com/s/files/1/0428/4727/3116/files/tefigojizige.pdf
    • https://cdn.shopify.com/s/files/1/0430/2218/8701/files/51721956822.pdf
    • https://cdn.shopify.com/s/files/1/0435/3510/6200/files/cengage_physics_for_neet.pdf
    • https://cdn.shopify.com/s/files/1/0430/9660/4825/files/67554305163.pdf
    • https://cdn.shopify.com/s/files/1/0435/3461/4688/files/jurowexijovijojuf.pdf
    • https://cdn.shopify.com/s/files/1/0432/9888/1704/files/xoletufodili.pdf
    • https://35bbd703-1fe7-43e3-9235-ce7acbf23cb7.filesusr.com/ugd/6cf0f5_503bbfe3c9f54c9bbc02813650b5bdda.pdf?index=true
    • https://bc0506f4-3393-4da9-861b-11bd7c52a2e0.filesusr.com/ugd/ffcbea_b63c4ef6aa7845f6b392f5ea3e739c3f.pdf?index=true
    • https://379f8986-62db-46ca-b373-a5d95778c10a.filesusr.com/ugd/a4ea6c_39c701caafb84ff29c59c83e13e86ad2.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000928c.bin
09f615d1d7b2258680f1c3f3b72ba2cc436a978ca7c1b386e848169d4c1dff52
pdf-font-stream PDF embedded font (sfnt) at offset 0x928C 4992 bytes
font_01_sfnt_off0000a3b9.bin
27025a2472c0e4c76a10212db6f365a9f905417798c1758439d59701da63ece4
pdf-font-stream PDF embedded font (sfnt) at offset 0xA3B9 15492 bytes
font_02_sfnt_off0000d3ae.bin
49436f94d5abf10ca6af8af9848174aab82dfe7bc58a5146411d238fd5c76648
pdf-font-stream PDF embedded font (sfnt) at offset 0xD3AE 16148 bytes