Malicious PDF — malware analysis report

Static analysis result for SHA-256 27b5ce82a3331586…

MALICIOUS

PDF

50.9 KB Created: 2020-08-02 23:05:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7113e62ca36c2827e69bd67f53d0e778 SHA-1: e2802c42a0edef16febec96c37378f04907ab60a SHA-256: 27b5ce82a33315869c0f0365c3ecb933d82f633a038e6917e0856b74188068b9
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains numerous embedded links, with a critical heuristic firing indicating a malicious redirector. One of the primary links, 'https://ttraff.com/pify?keyword=galletas+de+la+suerte', is flagged as malicious. The document also exhibits characteristics of a link farm, with many URLs pointing to Shopify domains, suggesting an attempt to obscure the malicious destination or distribute content broadly. No scripts were extracted, and the document body is largely unreadable binary data, but the presence of the malicious redirector is sufficient evidence of malicious intent.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=galletas+de+la+suerte
    • http://files.threeravenspianostudio.com/uploads/1/3/0/9/130969405/tonosinubawod-zategerosavip-bobolakuvo.pdf
    • http://files.throughthewoods.net/uploads/1/3/2/6/132683135/9606215a1431b31.pdf
    • http://files.shureepiano.com/uploads/1/3/0/7/130739280/batabepilusa.pdf
    • http://files.dakotadesigns.net/uploads/1/3/1/6/131606198/aade7bfed6.pdf
    • http://files.kittymunger.com/uploads/1/3/0/7/130776745/suwevatapobasuv_lodemido_bemom_rabawopolojow.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/1741436775.pdf
    • https://cdn.shopify.com/s/files/1/0437/3312/3221/files/keredopemize.pdf
    • https://cdn.shopify.com/s/files/1/0434/6154/2045/files/fosabodopavajidigufer.pdf
    • https://cdn.shopify.com/s/files/1/0431/0482/9589/files/60921650116.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/fakuwonilojovaxibudebu.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/45484104345.pdf
    • https://cdn.shopify.com/s/files/1/0431/5162/2306/files/19543720292.pdf
    • https://cdn.shopify.com/s/files/1/0429/7896/7703/files/56681578171.pdf
    • https://cdn.shopify.com/s/files/1/0432/4635/4594/files/97897999763.pdf
    • https://cdn.shopify.com/s/files/1/0433/6202/5624/files/c_read_a_text_file.pdf
    • https://cdn.shopify.com/s/files/1/0438/1910/6466/files/66556998865.pdf
    • https://cdn.shopify.com/s/files/1/0432/1637/1867/files/redopafujesolinodo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008830.bin
0f2abb240f0076a924c3a66dd6edd2ec9240ae0351811524fdcfc539301ad193
pdf-font-stream PDF embedded font (sfnt) at offset 0x8830 4848 bytes
font_01_sfnt_off000098b8.bin
c987a1a9031473c6a8562fe58f85c1fcf5dde06985813a69e4a15beb2989e41d
pdf-font-stream PDF embedded font (sfnt) at offset 0x98B8 11336 bytes