Malicious PDF — malware analysis report

Static analysis result for SHA-256 3887c9908fb9736a…

MALICIOUS

PDF

49.4 KB Created: 2020-08-06 06:04:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3fed4930be95f776a1e308d84f7ec8c9 SHA-1: aabae7454a23eeec98ed3d0080550d68f1f92401 SHA-256: 3887c9908fb9736a29188725609a6724e91bdb94e0d8d487065885fd44f62799
200 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

This PDF document contains numerous invisible links, a common technique for luring users into clicking malicious URLs. One prominent URL, https://ttraff.cc/pify?keyword=offenbach+barcarolle+piano+pdf, is identified as a malicious redirector. The document also exhibits parser evasion techniques and a large number of external PDF links, suggesting a sophisticated attempt to disguise malicious intent. The primary goal appears to be redirecting users to potentially harmful content.

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Invisible PDF links to CAPTCHA-themed web lure high PDF_CAPTCHA_LINK_LURE
    PDF contains invisible clickable link annotations that point to a CAPTCHA/capcha-themed web path. This is a common phishing and ClickFix-style routing pattern: the PDF itself is inert, while the linked page performs the credential prompt or fake verification.
  • Clickable PDF combines external action with parser-evasion structure high PDF_ACTION_PARSER_EVASION
    PDF has an external clickable URI together with object graph or xref structures that make parsers disagree, such as divergent duplicate objects, parser divergence, or xref offset mismatch. That combination is stronger than a plain link: the document is both an outward-action carrier and a parser-confusion/evasion sample.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=offenbach+barcarolle+piano+pdf
    • http://files.90daychallengewithamber.com/uploads/1/3/2/6/132695302/f4ab2758f2c.pdf
    • http://files.billmahonskigoldsmith.com/uploads/1/3/1/4/131482958/digulikonutanotuze.pdf
    • http://files.kev-art.com/uploads/1/3/2/8/132815181/zirepupirodalute.pdf
    • http://debekoxi.jtoppbecker.com/uploads/1/3/1/8/131871390/1194716.pdf
    • http://files.mindbody-solutions.net/uploads/1/3/1/4/131453917/a4bd0bd5.pdf
    • https://cdn.shopify.com/s/files/1/0434/7969/5526/files/recaptcha_ajax_response_text.pdf
    • https://cdn.shopify.com/s/files/1/0438/6953/6411/files/5767522539.pdf
    • https://cdn.shopify.com/s/files/1/0430/0144/6551/files/campbells_biology.pdf
    • https://cdn.shopify.com/s/files/1/0436/3524/5216/files/50740760092.pdf
    • https://cdn.shopify.com/s/files/1/0433/4754/2175/files/lezanepizowakagefezejegib.pdf
    • https://cdn.shopify.com/s/files/1/0432/7381/4182/files/pixokagewodovijigote.pdf
    • https://cdn.shopify.com/s/files/1/0429/4275/9071/files/latipepinixemafiwame.pdf
    • https://cdn.shopify.com/s/files/1/0433/4141/4552/files/xebofilapalolivajojeke.pdf
    • https://cdn.shopify.com/s/files/1/0432/5759/4011/files/vajajovokewajafusuwujexus.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/mofofuledezenededur.pdf
    • https://cdn.shopify.com/s/files/1/0430/9952/1181/files/hashset_time_complexity.pdf
    • https://cdn.shopify.com/s/files/1/0431/5529/2317/files/vewigodabixedufexu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000080f1.bin
1341e2d0cfa527c20ab58a0374d0992d08cef674bd0184ef9ea5a8fae95a8b28
pdf-font-stream PDF embedded font (sfnt) at offset 0x80F1 5232 bytes
font_01_sfnt_off000092ad.bin
64a5225bae5fe8325dab680ccd0d2275147cc0909fc736e6d93d23c262f7fe0a
pdf-font-stream PDF embedded font (sfnt) at offset 0x92AD 11448 bytes