Malicious PDF — malware analysis report

Static analysis result for SHA-256 42080eb4f44607c5…

MALICIOUS

PDF

43.4 KB Created: 2020-08-09 21:41:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 54cfeb51778e1d44f3c3d9249481703a SHA-1: 08e03cb798f555cf1854c80f5e6e409fde65aea9 SHA-256: 42080eb4f44607c59d46e9e08adfc9a828c4669137e67406c51245401d181c41
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, many of which point to external PDF files, suggesting a link farm or SEO poisoning tactic. One critical heuristic identified a link to a known malicious redirector, ttraff.cc, which is used to obscure the final destination. The document body contains text related to a financial PDF download, likely a lure to encourage clicks on the malicious links. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=corporate+finance+theory+and+practice+aswath+damodaran+pdf+download
    • http://keluzujow.galwayartacademy.com/uploads/1/3/2/8/132815123/9863949.pdf
    • http://files.liffordhealthcentre.com/uploads/1/3/0/8/130874284/5922e3fbe.pdf
    • http://files.wanderingwildandfree.com/uploads/1/3/1/1/131164537/xatinepapelawo_xetemisewonit_zamozuw_nidolomug.pdf
    • http://files.runforthefallennh.com/uploads/1/3/1/6/131606789/mabiwoxeregofajuxew.pdf
    • https://cdn.shopify.com/s/files/1/0435/5850/2563/files/fexegisel.pdf
    • https://cdn.shopify.com/s/files/1/0434/8094/0710/files/sublime_text_3_free_license.pdf
    • https://cdn.shopify.com/s/files/1/0434/5122/0120/files/causes_of_poverty_in_rural_areas.pdf
    • https://cdn.shopify.com/s/files/1/0435/2756/9576/files/annual_report_format.pdf
    • https://cdn.shopify.com/s/files/1/0430/4456/9242/files/xanuwuginirifirise.pdf
    • https://cdn.shopify.com/s/files/1/0439/5565/0718/files/moxepusanelivizikukadowoj.pdf
    • https://cdn.shopify.com/s/files/1/0429/2411/4076/files/d_d_4e.pdf
    • https://cdn.shopify.com/s/files/1/0430/9119/8112/files/89934876727.pdf
    • https://cdn.shopify.com/s/files/1/0430/4060/4313/files/list_of_adjectives_a_to_z.pdf
    • https://cdn.shopify.com/s/files/1/0428/7250/4483/files/56466318791.pdf
    • https://cdn.shopify.com/s/files/1/0431/3546/7669/files/guwokeduvudewebosenuwet.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006ad5.bin
34bb365c1446d410f4371afee23a085911f75a7d7d14dd6a4a79c5af73c95064
pdf-font-stream PDF embedded font (sfnt) at offset 0x6AD5 5492 bytes
font_01_sfnt_off00007d6f.bin
a350eb1825ef6ed1aaafb80cd80448993d1acef67aa76f5a6b2bc90b7b5e3d5c
pdf-font-stream PDF embedded font (sfnt) at offset 0x7D6F 10052 bytes