Malicious PDF — malware analysis report

Static analysis result for SHA-256 334a29baf6353a97…

MALICIOUS

PDF

48.5 KB Created: 2020-08-24 09:17:58 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 519e87157f2a12389ac930ddd748b2ca SHA-1: f26dcb10b255d33a8a3692c5c690e5f993f35171 SHA-256: 334a29baf6353a97ffcebe11b65b5afbc9c9d6950e6d59f1fdd7c410495f30e9
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a significant number of embedded external links, with one identified as a malicious redirector. This suggests a tactic to lure users to potentially harmful websites. The presence of a large link farm further supports this, indicating an attempt to manipulate search engine results or distribute malicious content through numerous indirect paths. No scripts were extracted, limiting the analysis of direct payload execution.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=platform+toolset%2527+v141%2527
    • http://jolusibam.rivercitygivers.com/uploads/1/3/0/8/130874388/b3ea954e2.pdf
    • http://vidojuxi.myeto.com/uploads/1/3/0/7/130775166/111b6f.pdf
    • http://files.2nurfm.com/uploads/1/3/1/4/131409200/7242120.pdf
    • http://files.msmacsschoolhouse.com/uploads/1/3/1/0/131070792/madoxor.pdf
    • http://saruxoro.wacooutdoorkitchens.com/uploads/1/3/0/7/130740025/7641887.pdf
    • https://cdn.shopify.com/s/files/1/0435/0722/0644/files/65918674562.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/bobidaxida.pdf
    • https://cdn.shopify.com/s/files/1/0431/0820/4708/files/73682813569.pdf
    • https://cdn.shopify.com/s/files/1/0463/0698/4098/files/brick_city_depot_instructions.pdf
    • https://cdn.shopify.com/s/files/1/0431/9733/3668/files/78714836430.pdf
    • https://cdn.shopify.com/s/files/1/0436/8603/5621/files/95918113324.pdf
    • https://cdn.shopify.com/s/files/1/0437/0048/6312/files/doxewik.pdf
    • https://cdn.shopify.com/s/files/1/0433/3164/9689/files/baixar_jogos_ppsspp_android_gratis.pdf
    • https://cdn.shopify.com/s/files/1/0437/0412/3557/files/66106000408.pdf
    • https://cdn.shopify.com/s/files/1/0436/3429/4937/files/55207283336.pdf
    • https://cdn.shopify.com/s/files/1/0437/4472/3098/files/jawuwawir.pdf
    • https://cdn.shopify.com/s/files/1/0438/0921/0529/files/random_number_between_1_and_9.pdf
    • https://cdn.shopify.com/s/files/1/0434/6429/4557/files/gst_authorised_signatory_letter_format_for_partnership.pdf
    • https://cdn.shopify.com/s/files/1/0435/0361/6165/files/mind_teasers.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com/s/files/1/0437/0048/6312/files/doxewik.p

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000681b.bin
36b48135f55f1dbc80741d73285e8d92592ec194b389d2a5b4c70168928eda80
pdf-font-stream PDF embedded font (sfnt) at offset 0x681B 5148 bytes
font_01_sfnt_off000079a0.bin
d896e41ffe638ceb7dbdfee07501a6961490a73b2cfcc06ef4c4d56c81c4b2c3
pdf-font-stream PDF embedded font (sfnt) at offset 0x79A0 10632 bytes
font_02_sfnt_off00009dfc.bin
a86f35426188812af2d148f74d9c4df64b241fa51c69dfa59b98590ca9361635
pdf-font-stream PDF embedded font (sfnt) at offset 0x9DFC 16532 bytes