Malicious PDF — malware analysis report

Static analysis result for SHA-256 357fab5413f5b2fd…

MALICIOUS

PDF

34.7 KB Created: 2020-08-17 17:18:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6e96c20a436b95be56278ce80189d28b SHA-1: 17b96708880233b4f41a7ee1ebdb9539a65f0f04 SHA-256: 357fab5413f5b2fd987805bcfa44906916de87cf8481861c0634816de573abe8
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a malicious redirector link disguised as a download button, aiming to lure users to a malicious site. The document also exhibits characteristics of a link farm, with numerous embedded links pointing to external resources, some of which are benign Shopify URLs, but one points to known malicious redirector infrastructure. The primary malicious URL identified is https://ttraff.cc/pify?keyword=alphabet+tracing+sheets+for+preschoolers.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=alphabet+tracing+sheets+for+preschoolers
    • http://ratipew.reikibyleslie.com/uploads/1/3/1/4/131437402/39aecb85993006.pdf
    • https://cdn.shopify.com/s/files/1/0432/5185/9616/files/66973213564.pdf
    • https://cdn.shopify.com/s/files/1/0437/5488/1175/files/canada_visa_application_form_in_oman.pdf
    • https://cdn.shopify.com/s/files/1/0438/6983/1323/files/ratopasaxazag.pdf
    • https://cdn.shopify.com/s/files/1/0431/2127/9138/files/biohazard_5_game_apk.pdf
    • https://cdn.shopify.com/s/files/1/0434/8510/2237/files/batojuzaki.pdf
    • https://cdn.shopify.com/s/files/1/0430/4296/3613/files/xalexififipobarumabir.pdf
    • https://cdn.shopify.com/s/files/1/0437/1913/1285/files/8939373794.pdf
    • https://cdn.shopify.com/s/files/1/0428/6811/3574/files/15415416135.pdf
    • https://cdn.shopify.com/s/files/1/0434/0698/3335/files/curso_de_bambuterapia.pdf
    • https://cdn.shopify.com/s/files/1/0440/0994/7301/files/vozuzubuferopewabomowem.pdf
    • https://cdn.shopify.com/s/files/1/0438/6878/2757/files/75650250398.pdf
    • https://cdn.shopify.com/s/files/1/0428/4225/9612/files/palida.pdf
    • https://cdn.shopify.com/s/files/1/0435/3818/6394/files/gloomhaven_envelope_x.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004b78.bin
dc03374756a222ec0920d44538788a588b16e7c4e88424c905da947265839316
pdf-font-stream PDF embedded font (sfnt) at offset 0x4B78 5408 bytes
font_01_sfnt_off00005dcb.bin
e633b4c7b52104887fac7a48c4a6d23bd7bf2c0be9514e256854113236f99e2b
pdf-font-stream PDF embedded font (sfnt) at offset 0x5DCB 9400 bytes