Malicious PDF — malware analysis report

Static analysis result for SHA-256 43c148c99552699d…

MALICIOUS

PDF

96.5 KB Created: 2020-08-10 14:23:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 757e1004f2e54a76c9655fd6197abb71 SHA-1: 6d6ee0faf82e4626efe0bff5771ec1a24df7bad9 SHA-256: 43c148c99552699df779ac68c2e1831d5bf41de3d283cbf97419a5b13afebd0f
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. The document body, though heavily obfuscated, contains the text 'Buddhist holy book tripitaka pdf' and the malicious URL, suggesting a lure to trick users into clicking the link. The PDF also contains a large number of external links, many hosted on 'cdn.shopify.com', which is flagged as a link farm. The primary malicious IOC is the redirector URL.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=buddhist+holy+book+tripitaka+pdf
    • http://files.eatclaylove.com/uploads/1/3/0/9/130969825/fogatusolipex-xuzorepafovoni-rupizolik.pdf
    • http://files.amirajnorris.com/uploads/1/3/1/4/131438541/dokirabizevepo.pdf
    • http://lirebej.oilmyworld.net/uploads/1/3/0/7/130776644/kubotilewijeval_bodoluzegimesi_fanujabujeka_jetaxuxuxovasuz.pdf
    • https://cdn.shopify.com/s/files/1/0430/7845/1351/files/ontology_computer_science.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/fokadexowigexavutezirero.pdf
    • https://cdn.shopify.com/s/files/1/0428/8148/2919/files/zozirejek.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/niroduwo.pdf
    • https://cdn.shopify.com/s/files/1/0432/1984/5278/files/8264963821.pdf
    • https://cdn.shopify.com/s/files/1/0434/4587/8950/files/68913676467.pdf
    • https://cdn.shopify.com/s/files/1/0431/9074/7293/files/91077562362.pdf
    • https://cdn.shopify.com/s/files/1/0431/8255/5300/files/81375793432.pdf
    • https://cdn.shopify.com/s/files/1/0431/1236/6229/files/40932542539.pdf
    • https://cdn.shopify.com/s/files/1/0440/4363/2805/files/walmart_cashier_application.pdf
    • https://cdn.shopify.com/s/files/1/0430/6341/0839/files/bozoxoxivijawexi.pdf
    • https://cdn.shopify.com/s/files/1/0432/5546/4104/files/mapinowevudamaxomu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 11

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a483.bin
3c2648050810f586ce0102a5b24939c302035e1b5b61534558fe40907ee7af16
pdf-font-stream PDF embedded font (sfnt) at offset 0xA483 7380 bytes
font_01_sfnt_off0000bdba.bin
622be3f7f53fa9fa28691a9a43c054807adb29ee27bf330020449a8bf67fd410
pdf-font-stream PDF embedded font (sfnt) at offset 0xBDBA 5144 bytes
font_02_sfnt_off0000cf36.bin
1060bf2d4e86c9af3de6f9f05a0006ee37e218874003c9482b55f88de196339f
pdf-font-stream PDF embedded font (sfnt) at offset 0xCF36 2932 bytes
font_03_sfnt_off0000db01.bin
bf2dc291edd9bd913f080d6ead5f729c668e8c33b84194e09990e3090c3a8fd9
pdf-font-stream PDF embedded font (sfnt) at offset 0xDB01 4496 bytes
font_04_sfnt_off0000e981.bin
bf75df115c132fe68d1d51022058d8d27e1572d1272ed0116f6ac83685479fa0
pdf-font-stream PDF embedded font (sfnt) at offset 0xE981 5324 bytes
font_05_sfnt_off0000f8ed.bin
fbc23f5b4c8ec8b4a522772817c8ab8873577ed758308134d29a2da86dbacc6c
pdf-font-stream PDF embedded font (sfnt) at offset 0xF8ED 5156 bytes
font_06_sfnt_off00010ad0.bin
f25071f9398ddd7c254128f0c17a6bffae17195d9f3c4aa54d4c1e35e92e259d
pdf-font-stream PDF embedded font (sfnt) at offset 0x10AD0 7268 bytes
font_07_sfnt_off00011e6c.bin
e87407d04292281d8aa976dadcb7a0cd886c33b6b42349589ba4b888dae5faed
pdf-font-stream PDF embedded font (sfnt) at offset 0x11E6C 13596 bytes
font_08_sfnt_off0001479b.bin
05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176
pdf-font-stream PDF embedded font (sfnt) at offset 0x1479B 4324 bytes
font_09_sfnt_off0001559e.bin
e8829d928545eaa3710c314671794eaff13e12794608f569984ce0199d6352a4
pdf-font-stream PDF embedded font (sfnt) at offset 0x1559E 2836 bytes
font_10_sfnt_off00016134.bin
79487ce31b2698095fd0dd722bb60855664500526b63603cf1403e0391ae5408
pdf-font-stream PDF embedded font (sfnt) at offset 0x16134 4892 bytes