Malicious PDF — malware analysis report

Static analysis result for SHA-256 4336b0b610334c76…

MALICIOUS

PDF

49.1 KB Created: 2020-08-18 14:32:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3b97ae435ea41c3968bf222d385982db SHA-1: b7986c23095f5efed85353909786742d697255b0 SHA-256: 4336b0b610334c766f83ba2428e17b1399fc710c92e89ea55c9affffd68736e6
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a significant number of embedded links, with a heuristic firing indicating a link farm designed to direct users to external resources. One of these links points to a known malicious redirector service (ttraff.com), suggesting an attempt to obscure the final malicious destination. The document body itself contains the same song title and URLs, reinforcing the link farm nature of the document. No scripts were extracted, limiting the analysis to the document's structure and embedded links.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=ain%2527+t+nobody+tell+me+nothing+song
    • http://files.thehonestlycleancompany.com/uploads/1/3/1/6/131606256/lekozulefekafixidap.pdf
    • http://files.staloysiuschurch.com/uploads/1/3/1/3/131398477/wasugotisirusafa.pdf
    • http://files.belaccommunications.com/uploads/1/3/0/8/130873961/f19ee2ad2c7d9f.pdf
    • http://files.isoandbusinessexpert.com/uploads/1/3/0/8/130813797/noxodak.pdf
    • https://cdn.shopify.com/s/files/1/0431/8262/0834/files/16508238525.pdf
    • https://cdn.shopify.com/s/files/1/0440/4294/4677/files/renebevanasujukobipoloju.pdf
    • https://cdn.shopify.com/s/files/1/0431/6191/1458/files/unearthed_arcana_ranger_revised.pdf
    • https://cdn.shopify.com/s/files/1/0428/4468/4454/files/fuzoririk.pdf
    • https://cdn.shopify.com/s/files/1/0433/3263/2730/files/13073402127.pdf
    • https://cdn.shopify.com/s/files/1/0432/9753/8203/files/rolomifadoxepituvapoxufib.pdf
    • https://cdn.shopify.com/s/files/1/0434/4964/7271/files/85021260065.pdf
    • https://cdn.shopify.com/s/files/1/0431/7901/6360/files/bemba_proverbs_and_meaning.pdf
    • https://cdn.shopify.com/s/files/1/0440/6099/9830/files/kokalosibeguzadu.pdf
    • https://cdn.shopify.com/s/files/1/0437/9728/2977/files/varevawal.pdf
    • https://cdn.shopify.com/s/files/1/0431/5981/4306/files/bolsa_de_valores_de_lima.pdf
    • https://cdn.shopify.com/s/files/1/0428/4760/0796/files/jofapegijomedufegotexiw.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/fokukivovasogu.pdf
    • https://cdn.shopify.com/s/files/1/0439/4283/8427/files/bixal.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007436.bin
8b41cb9ed0a32ce0408a80d9f249344688d5f5c30d6c38dff72a64c290cfde29
pdf-font-stream PDF embedded font (sfnt) at offset 0x7436 4984 bytes
font_01_sfnt_off00008503.bin
6e8b4ded3e14f12198d78ba11a70a1f04065eb6db2b95873bcdbf845be1ae91f
pdf-font-stream PDF embedded font (sfnt) at offset 0x8503 10456 bytes
font_02_sfnt_off0000a8cc.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0xA8CC 4324 bytes