Malicious PDF — malware analysis report

Static analysis result for SHA-256 fc1650c7c2e856cb…

MALICIOUS

PDF

41.6 KB Created: 2020-08-08 07:30:40 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6e000be94c6313e0937cc0e133b01471 SHA-1: ae527d19039c6838e3bfb3066be2d85670ceecc0 SHA-256: fc1650c7c2e856cb33ca06275c59ceac320ae5a6dc669a6c3087418325c3c997
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a mass external link farm, with a primary link pointing to a known malicious redirector. The document body, though heavily obfuscated, contains the URL that leads to the redirector. This suggests the document's purpose is to redirect the user to malicious infrastructure, likely for further exploitation or credential harvesting.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=canopus+in+argos+pdf
    • http://files.myscarpaalta.com/uploads/1/3/0/7/130775518/af2bfa70b8e5421.pdf
    • http://gabulaxaf.cedarburgtoyco.com/uploads/1/3/2/7/132712207/fivow.pdf
    • http://files.aurum-et-argentum.net/uploads/1/3/0/8/130874204/nanamar.pdf
    • https://cdn.shopify.com/s/files/1/0429/7952/4759/files/nuwagowus.pdf
    • https://cdn.shopify.com/s/files/1/0428/2672/7580/files/12872604741.pdf
    • https://cdn.shopify.com/s/files/1/0435/4277/3914/files/24574179842.pdf
    • https://cdn.shopify.com/s/files/1/0437/6290/9335/files/14258051364.pdf
    • https://cdn.shopify.com/s/files/1/0430/9866/9220/files/discovering_biological_psychology_2nd_edition.pdf
    • https://cdn.shopify.com/s/files/1/0434/6842/3334/files/permaculture_a_designers_manual.pdf
    • https://cdn.shopify.com/s/files/1/0430/8962/5250/files/88912504352.pdf
    • https://cdn.shopify.com/s/files/1/0432/7673/0533/files/84000827375.pdf
    • https://cdn.shopify.com/s/files/1/0431/4392/1820/files/the_legacy_of_isaiah_berlin.pdf
    • https://cdn.shopify.com/s/files/1/0437/5317/7237/files/96906929798.pdf
    • https://cdn.shopify.com/s/files/1/0431/8062/1984/files/cfa_level_2_schweser.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000059cb.bin
3ea9dc0fe5daeba8b7c1286de8752a991578e51b79301a8010be3d8f06b4997c
pdf-font-stream PDF embedded font (sfnt) at offset 0x59CB 3080 bytes
font_01_sfnt_off000064d3.bin
479353159c36047bf221504a97af2cf4c0a440c548ab679ab5d9a3990f00d3ec
pdf-font-stream PDF embedded font (sfnt) at offset 0x64D3 5084 bytes
font_02_sfnt_off00007629.bin
8c7c8421928e94dc6e36e9d8bd4f0865b05be31439a215b0cf26ff8e5e6368a0
pdf-font-stream PDF embedded font (sfnt) at offset 0x7629 10292 bytes