Malicious PDF — malware analysis report

Static analysis result for SHA-256 25664b85f953179c…

MALICIOUS

PDF

202.3 KB Created: 2020-08-22 10:45:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c629895e5be8125e18a6f9fcb99a5ec3 SHA-1: 44fea461e056ab05fcdbaffd845d8a4b378e7512 SHA-256: 25664b85f953179cedd9423aca7fd42bf16b7b4a5b26d7a0b38a8687ae080b3c
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a malicious redirector link pointing to ttraff.com, which is also present in the document body. This indicates an attempt to lure the user to a malicious site. The heuristic for 'SE_ADVANCE_FEE_SCAM_LURE' further suggests the document's content is designed to trick users into clicking the link, likely for financial gain or to download further malware. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=emilie+autumn+marry+me+sheet+music
    • http://files.berghutteskiclub.com/uploads/1/3/1/3/131380138/bawudur-wadexetugew.pdf
    • http://kubibulug.greatglasspumpkinpatch.com/uploads/1/3/2/7/132740414/8f3aefe.pdf
    • http://files.tacdlo.org/uploads/1/3/0/7/130775429/8690191.pdf
    • http://xedetikok.2dplan-shop.com/uploads/1/3/1/6/131606349/78353.pdf
    • https://cdn.shopify.com/s/files/1/0429/9957/8773/files/56803434634.pdf
    • https://cdn.shopify.com/s/files/1/0431/4916/4693/files/responsive_html_css_template_free.pdf
    • https://cdn.shopify.com/s/files/1/0437/0304/2216/files/farm_pro_tractor.pdf
    • https://cdn.shopify.com/s/files/1/0433/5416/1310/files/19394906008.pdf
    • https://cdn.shopify.com/s/files/1/0430/0124/9955/files/45855026157.pdf
    • https://cdn.shopify.com/s/files/1/0433/9764/4449/files/13307675710.pdf
    • https://cdn.shopify.com/s/files/1/0435/6535/1071/files/58951275320.pdf
    • https://cdn.shopify.com/s/files/1/0427/9199/3500/files/24049730801.pdf
    • https://cdn.shopify.com/s/files/1/0437/3548/2529/files/23699854495.pdf
    • https://cdn.shopify.com/s/files/1/0449/8348/4574/files/hp_envy_bluetooth_driver_windows_10.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/xaxigeruver.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000299bb.bin
746cda19d0a45b0d6108c63ff8192b2f88c2fff5e5937e692a7cb04b31166607
pdf-font-stream PDF embedded font (sfnt) at offset 0x299BB 6588 bytes
font_01_sfnt_off0002aa35.bin
bd5933684da4f0366d87a583646c4179099ff2666b633ae51b643024c5a27829
pdf-font-stream PDF embedded font (sfnt) at offset 0x2AA35 5100 bytes
font_02_sfnt_off0002bb53.bin
8b05efbc106625d60a0fec291d44ecf14aa4ac1934ccca76a5b7d85fed62082c
pdf-font-stream PDF embedded font (sfnt) at offset 0x2BB53 4712 bytes
font_03_sfnt_off0002cc58.bin
0d2abc8aadb26c4dbd16cbcd7510e4b41034a39edd722de6381b4d66595d5300
pdf-font-stream PDF embedded font (sfnt) at offset 0x2CC58 14096 bytes
font_04_sfnt_off0002f978.bin
da3f5473c50d2bf108595ab7f7b5929b2e0bdab72f4b4444c4ff0785fc66f4ae
pdf-font-stream PDF embedded font (sfnt) at offset 0x2F978 16964 bytes
font_05_sfnt_off00031169.bin
f27f1dab863be407bc80ce69f069aaa000ada345c50a5fba1d6b915b5f603bb6
pdf-font-stream PDF embedded font (sfnt) at offset 0x31169 1736 bytes