Malicious PDF — malware analysis report

Static analysis result for SHA-256 1dc9da52bde4a9f8…

MALICIOUS

PDF

43.6 KB Created: 2020-08-15 01:02:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5423dcd49471905ae9aa61bff0c07c39 SHA-1: d5e415629539cec27f5931fff789b6b0f25f1e0c SHA-256: 1dc9da52bde4a9f8a7c1647524496f88799d20537e04ec3ed51ccfe4f06c126e
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a significant number of external links, many of which point to what appears to be a link farm designed for SEO manipulation. One of the primary links, 'https://ttraff.cc/pify?keyword=page+builder+html+template', is identified as a malicious redirector. This suggests the document's purpose is to drive traffic to malicious infrastructure, likely for further exploitation or phishing. No scripts were extracted, limiting the analysis of direct payload delivery mechanisms.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=page+builder+html+template
    • http://files.designsbydebllc.com/uploads/1/3/1/3/131380308/3202943.pdf
    • http://files.basketball.rcsportscards.com/uploads/1/3/1/8/131872273/38f3e1b6683cd.pdf
    • http://files.centerforwomenfaithandleadership.org/uploads/1/3/0/7/130776602/tovirin.pdf
    • http://files.songdropshop.com/uploads/1/3/2/6/132682338/jagap_xikawumepobi_nefovebufez_telufuwume.pdf
    • https://cdn.shopify.com/s/files/1/0440/7109/2376/files/the_other_wes_moore_audiobook.pdf
    • https://cdn.shopify.com/s/files/1/0428/8764/3302/files/32981165915.pdf
    • https://cdn.shopify.com/s/files/1/0433/9158/2357/files/ximelogote.pdf
    • https://cdn.shopify.com/s/files/1/0433/3935/0181/files/wurolamepeze.pdf
    • https://cdn.shopify.com/s/files/1/0428/8000/8355/files/giwazanava.pdf
    • https://cdn.shopify.com/s/files/1/0437/0061/7381/files/36889741501.pdf
    • https://cdn.shopify.com/s/files/1/0431/8347/2791/files/calculus_1_review_problems.pdf
    • https://cdn.shopify.com/s/files/1/0432/6214/8763/files/15116468631.pdf
    • https://cdn.shopify.com/s/files/1/0434/9899/5877/files/health_effects_of_water_pollution.pdf
    • https://cdn.shopify.com/s/files/1/0427/7148/0742/files/58848008998.pdf
    • https://cdn.shopify.com/s/files/1/0431/0840/1316/files/96724182144.pdf
    • https://cdn.shopify.com/s/files/1/0432/2210/6272/files/autodesk_revit_training.pdf
    • https://cdn.shopify.com/s/files/1/0436/3862/0318/files/81086271453.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006d3f.bin
b129410bc907694afc87c6135b5019e7950aedd619588358031dd3f87f0c0845
pdf-font-stream PDF embedded font (sfnt) at offset 0x6D3F 5336 bytes
font_01_sfnt_off00007f2a.bin
4dd6a19bde6fe7ba835c3255e6c04042ce4fabd04ce5da1a847b6b2241ae3e5a
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F2A 9948 bytes