Malicious PDF — malware analysis report

Static analysis result for SHA-256 4969c4cfbace1d70…

MALICIOUS

PDF

50.4 KB Created: 2020-08-11 14:54:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4fa9ab1cb9f5d4a37e8a109803c59093 SHA-1: 00e5a819584396e99cc7812710f5ca87bf8bf1a3 SHA-256: 4969c4cfbace1d70ebf7b9e56d75931d86f2834d8159f32447182d52683f52d5
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a significant number of embedded links, with a critical heuristic firing indicating a link farm pointing to a redirector service. The primary URL, 'https://ttraff.cc/pify?keyword=biogas+project+pdf+in+marathi', is identified as a malicious redirector. This suggests the document's purpose is to lure users into clicking these links, which likely lead to malicious content or further exploitation. No scripts were extracted, and the document body is heavily obfuscated.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=biogas+project+pdf+in+marathi
    • http://files.rollingthunderky5.org/uploads/1/3/1/3/131398194/3d9b094f849b6.pdf
    • http://geserine.cyclingsportscenter.com/uploads/1/3/1/4/131437423/xutovasolemiram_kipogalonuwemi_limibinuge_rovuge.pdf
    • http://files.welshpromscymru.com/uploads/1/3/0/8/130873715/6479861.pdf
    • http://fedupafi.rollepodiatry.co.uk/uploads/1/3/2/6/132696030/152053.pdf
    • http://files.pratasabavacation.com/uploads/1/3/1/4/131409333/1595925.pdf
    • https://cdn.shopify.com/s/files/1/0431/7007/0690/files/crossfit_benchmarks.pdf
    • https://cdn.shopify.com/s/files/1/0430/0292/1111/files/time_attendance_system_installation.pdf
    • https://cdn.shopify.com/s/files/1/0431/1285/7754/files/tin_cup_soundtrack.pdf
    • https://cdn.shopify.com/s/files/1/0440/1322/4094/files/vazujabiwepuvukafojejobon.pdf
    • https://cdn.shopify.com/s/files/1/0436/9140/9562/files/vulemunozabawiwidi.pdf
    • https://cdn.shopify.com/s/files/1/0434/0649/1797/files/51404578309.pdf
    • https://cdn.shopify.com/s/files/1/0430/7304/4634/files/85646233103.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/tovovowegafakaroseras.pdf
    • https://cdn.shopify.com/s/files/1/0432/8911/6836/files/gulikorabinuvi.pdf
    • https://cdn.shopify.com/s/files/1/0437/2476/7383/files/afcat_previous_question_paper.pdf
    • https://cdn.shopify.com/s/files/1/0435/6092/7393/files/phil_wickham_heaven_song.pdf
    • https://cdn.shopify.com/s/files/1/0428/8148/2919/files/zexusexesugepana.pdf
    • https://cdn.shopify.com/s/files/1/0431/9356/5342/files/importance_of_auditing_financial_statements.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007891.bin
589c991984ea6b33cd54363ce9d03a8eb4a79771c9344abc9cf437ed5ab02fb7
pdf-font-stream PDF embedded font (sfnt) at offset 0x7891 5660 bytes
font_01_sfnt_off00008bb0.bin
1bbe67141762a84743599c417aea3d258799e0816e75d4d2b51fdf376545d5b0
pdf-font-stream PDF embedded font (sfnt) at offset 0x8BB0 10344 bytes
font_02_sfnt_off0000aefa.bin
d5dc42aae4a247aad3c983bbe8ba70c2c24db5b11c8364a4d7a450a2bfba1cc8
pdf-font-stream PDF embedded font (sfnt) at offset 0xAEFA 3252 bytes