Malicious PDF — malware analysis report

Static analysis result for SHA-256 fcbb679b57adcdfc…

MALICIOUS

PDF

45.6 KB Created: 2020-08-23 08:54:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 97abc73240b7774d831500c8a753b2a2 SHA-1: dd4ca2602a74bdd35a10292f61871483e54fe367 SHA-256: fcbb679b57adcdfccdeadd1ec6c1921a9f3ffd3f3cafa6cc398d78effe9fa458
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, many of which point to external resources. One of these links, 'https://ttraff.ru/pify?keyword=bestiario+cortazar+pdf', is identified as a known malicious redirector. The document's structure and the presence of numerous links suggest it is designed to lure users to malicious websites, potentially for further exploitation or credential harvesting.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=bestiario+cortazar+pdf
    • http://files.hubbymoments.com/uploads/1/3/1/6/131607467/menajagasuli.pdf
    • https://cdn.shopify.com/s/files/1/0431/5725/8395/files/wogodofegajexalamabiz.pdf
    • https://cdn.shopify.com/s/files/1/0432/8708/5222/files/adobe_indesign_cs4_tutorial.pdf
    • https://cdn.shopify.com/s/files/1/0438/2556/1757/files/kuvolajivavokejevavi.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/rabilividobakomitunaxizug.pdf
    • https://cdn.shopify.com/s/files/1/0433/9659/5868/files/8763040051.pdf
    • https://cdn.shopify.com/s/files/1/0432/9806/2501/files/gib_aqualine_sheet_sizes.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/70913092576.pdf
    • https://cdn.shopify.com/s/files/1/0429/0789/3919/files/mufajere.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/30740110423.pdf
    • https://cdn.shopify.com/s/files/1/0429/0881/1427/files/narrow_minded_productions.pdf
    • https://cdn.shopify.com/s/files/1/0428/1915/8183/files/fokevenilup.pdf
    • https://cdn.shopify.com/s/files/1/0436/1653/4690/files/71879485760.pdf
    • https://cdn.shopify.com/s/files/1/0427/4916/5734/files/62286918011.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007609.bin
8926e36cb2cb32916d3a5311052221402a2ab1188617cc874411fab693eb5f6f
pdf-font-stream PDF embedded font (sfnt) at offset 0x7609 5216 bytes
font_01_sfnt_off000087e0.bin
c323b0edbd3c40c9c2a0228d6bc99ccfc0ab20e82af53e8f77daefe8249e94af
pdf-font-stream PDF embedded font (sfnt) at offset 0x87E0 9972 bytes