Malicious PDF — malware analysis report

Static analysis result for SHA-256 40fb5b410ee92178…

MALICIOUS

PDF

152.5 KB Created: 2020-08-03 16:01:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 53dc21e82cf226e5492a02472c35c7a4 SHA-1: 6afcdd055a0bc9a47f5ef901ad71ceb3e67d822a SHA-256: 40fb5b410ee9217861931d2f50904a9113b1ed3ab387881fcec969f6d625bb9f
100 Risk Score

Malware Insights

MITRE ATT&CK
T1059.003 Windows Command Shell T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=catalog+panasonic+wide+series+pdf'. Additionally, a high severity heuristic indicates a 'Clipboard command execution lure', instructing the user to interact with shell commands. This suggests the document's primary purpose is to trick the user into navigating to the malicious URL, which likely serves as a dropper for further malicious activity.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=catalog+panasonic+wide+series+pdf
    • http://files.wintergreenmapleproducts.com/uploads/1/3/1/6/131606431/d9cccae083c05.pdf
    • http://files.whitecloudsweb.com/uploads/1/3/1/4/131406831/poxurakotekon-vosomo-morapuxamutep.pdf
    • http://files.bxd-ia.org/uploads/1/3/1/4/131437484/tukenujinir_kemuji_nugenobijov_lugaxe.pdf
    • http://files.thegardensatsancarlos.com/uploads/1/3/1/4/131409557/23222.pdf
    • http://files.aloannomore.com/uploads/1/3/0/7/130739831/5141397.pdf
    • https://cdn.shopify.com/s/files/1/0429/9702/2871/files/pujowivofiwej.pdf
    • https://cdn.shopify.com/s/files/1/0430/9578/5629/files/pigim.pdf
    • https://cdn.shopify.com/s/files/1/0431/8402/9854/files/31921263350.pdf
    • https://cdn.shopify.com/s/files/1/0434/0904/7708/files/initial_counseling_pvt_spc.pdf
    • https://cdn.shopify.com/s/files/1/0434/1284/8790/files/duzomut.pdf
    • https://cdn.shopify.com/s/files/1/0430/2422/0321/files/bazezanumoru.pdf
    • https://cdn.shopify.com/s/files/1/0431/2249/1541/files/fable_3_save_editor.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/kijajakunij.pdf
    • https://cdn.shopify.com/s/files/1/0431/3926/8774/files/79451305561.pdf
    • https://cdn.shopify.com/s/files/1/0430/8025/3593/files/denutujizukep.pdf
    • https://cdn.shopify.com/s/files/1/0429/7257/7946/files/39704178854.pdf
    • https://cdn.shopify.com/s/files/1/0431/8412/8151/files/segedovatoxixefasaba.pdf
    • https://cdn.shopify.com/s/files/1/0435/7462/4419/files/65975658720.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001cb8a.bin
91c65d4daef29bab276e56b606f9c5013e4f13bc29c78e9eee33dd87ab02342c
pdf-font-stream PDF embedded font (sfnt) at offset 0x1CB8A 2996 bytes
font_01_sfnt_off0001d64e.bin
15cb4e17ab44d41bb50586834b1991177122fa72fe04e7d17835f89d889c3f76
pdf-font-stream PDF embedded font (sfnt) at offset 0x1D64E 5320 bytes
font_02_sfnt_off0001e87a.bin
2faa0f2a6343cc27b43200fe628bbb857b48ca7e2ff4ecc114254f4ecd3c85ed
pdf-font-stream PDF embedded font (sfnt) at offset 0x1E87A 9380 bytes
font_03_sfnt_off000202e4.bin
3967eef9cc067d979744ce9f046e1133722dd0db0ebed51fbd86ae0627b2e09c
pdf-font-stream PDF embedded font (sfnt) at offset 0x202E4 18052 bytes
font_04_sfnt_off00023aa8.bin
1b3a7c1b7bc451495b69e6c2dc925dfa634ebf3cd17a1c22ac82dde46aeedc8f
pdf-font-stream PDF embedded font (sfnt) at offset 0x23AA8 16260 bytes