Malicious PDF — malware analysis report

Static analysis result for SHA-256 e73b3d4fcea7a53a…

MALICIOUS

PDF

53.1 KB Created: 2020-08-27 21:28:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bbec9579faf0cfb3d1f5c4a26f37d53b SHA-1: ae150e75aaab986dd60d7b9f746a7980f00bfe93 SHA-256: e73b3d4fcea7a53a52fd03d4c878abcacbd3a59e40de38c655594508397402e0
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.001 User Execution: Malicious Link

The PDF contains a heuristic firing for a malicious redirector link, which is also present in the document body. This link, 'https://ttraff.cc/pify?keyword=theories+of+counseling+and+psychotherapy+pdf', redirects to malicious infrastructure. The PDF also contains a link farm heuristic, indicating a large number of external links, many of which point to Shopify domains hosting other PDFs. The ML classifier strongly flagged this PDF as malicious. The primary attack vector appears to be social engineering via a deceptive document title and a malicious link.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=theories+of+counseling+and+psychotherapy+pdf
    • http://rifarana.barkingwithbutler.com/uploads/1/3/0/9/130969042/bd26b43085.pdf
    • https://cdn.shopify.com/s/files/1/0431/4211/9592/files/dipisuwezakadobo.pdf
    • https://cdn.shopify.com/s/files/1/0461/9154/2423/files/bokulokenudeguvoxukaw.pdf
    • https://cdn.shopify.com/s/files/1/0433/7877/0076/files/characteristics_of_scientific_method_of_research.pdf
    • https://cdn.shopify.com/s/files/1/0430/7409/3217/files/dozunadanexurujefed.pdf
    • https://cdn.shopify.com/s/files/1/0435/0921/9492/files/lewuluzupafoxoba.pdf
    • https://cdn.shopify.com/s/files/1/0432/6155/8944/files/35901952027.pdf
    • https://cdn.shopify.com/s/files/1/0430/8254/7361/files/88312387382.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/mosagewenusuwaguxizekud.pdf
    • https://cdn.shopify.com/s/files/1/0437/5245/6346/files/avast_cleanup_pro_gratis.pdf
    • https://cdn.shopify.com/s/files/1/0437/8676/4446/files/dalureralutebubosidebu.pdf
    • https://cdn.shopify.com/s/files/1/0440/9786/3832/files/wezarozowatovaj.pdf
    • https://cdn.shopify.com/s/files/1/0430/2913/5521/files/gmo_meaning.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000708e.bin
873c6d0bd4cc86f2ed3bab55c9d1fb4a1cc8a5f7374ea748977b0232d6186ec3
pdf-font-stream PDF embedded font (sfnt) at offset 0x708E 5468 bytes
font_01_sfnt_off00008323.bin
094782de089b98e5648d94d8fbb3edc6fef9a769d01337a50d5ac67cf894848f
pdf-font-stream PDF embedded font (sfnt) at offset 0x8323 14504 bytes
font_02_sfnt_off0000b165.bin
532315dfdc59b350d447ad91845dd8cc72a836e684f536ab9a4305dc5b53fb8e
pdf-font-stream PDF embedded font (sfnt) at offset 0xB165 16204 bytes