Malicious PDF — malware analysis report

Static analysis result for SHA-256 4b825d1512c47bb5…

MALICIOUS

PDF

44.7 KB Created: 2020-08-05 02:24:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 937bd18db9da17da52eb7259960de20d SHA-1: 2fa25713e2996c2d0e1afbe17de7789903e20383 SHA-256: 4b825d1512c47bb506ab6e8b49298ed461d0770b00bed14553d8c923534337ea
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.ru/wb?keyword=manual%20del%20conductor%20puerto%20rico%202018'. Additionally, it exhibits characteristics of a PDF SEO link farm, embedding numerous links to external PDF files, many hosted on shopify.com subdomains. The document body, though heavily obfuscated, contains the same redirector URL, reinforcing the malicious intent. The primary attack pattern involves luring the user to a malicious site via a deceptive document.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wb?keyword=manual%20del%20conductor%20puerto%20rico%202018
    • http://files.destrierbooks.com/uploads/1/3/1/4/131437330/3370808.pdf
    • http://files.fancyworldusa.com/uploads/1/3/1/3/131398195/vosesabugunor.pdf
    • http://files.sklallamwarriors.com/uploads/1/3/0/7/130739509/16ad61921.pdf
    • http://files.simply-scripted.com/uploads/1/3/0/7/130739265/1714467.pdf
    • http://files.minecraftintheclassroom.com/uploads/1/3/1/1/131164358/ximuwozo-viparatexerom.pdf
    • https://cdn.shopify.com/s/files/1/0439/1016/8744/files/21901528156.pdf
    • https://cdn.shopify.com/s/files/1/0433/6504/0286/files/vokogokax.pdf
    • https://cdn.shopify.com/s/files/1/0433/7218/3703/files/7449852734.pdf
    • https://cdn.shopify.com/s/files/1/0430/9660/4825/files/the_wire_season_3_torrent.pdf
    • https://cdn.shopify.com/s/files/1/0434/9856/9888/files/midotijukuzaxuzufije.pdf
    • https://cdn.shopify.com/s/files/1/0428/6991/5814/files/76122138237.pdf
    • https://cdn.shopify.com/s/files/1/0428/7240/6179/files/49216738524.pdf
    • https://cdn.shopify.com/s/files/1/0431/6977/5782/files/telebevirosalanidirep.pdf
    • https://cdn.shopify.com/s/files/1/0433/8299/7148/files/synecdoche_new_york_analysis.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/mojijemorewowasimagaxo.pdf
    • https://cdn.shopify.com/s/files/1/0431/4297/1553/files/vakagixexanedirufofepupex.pdf
    • https://cdn.shopify.com/s/files/1/0431/0522/2813/files/wofovuxi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005282.bin
a223b10b75a4df87f7af56724a0d61d58134c457ae082209ddfd2ddee3f9d574
pdf-font-stream PDF embedded font (sfnt) at offset 0x5282 5296 bytes
font_01_sfnt_off00006484.bin
190ed3ca2f366942097257119aba5b5d93bc68e5c3ec07997be340eb95d35fcf
pdf-font-stream PDF embedded font (sfnt) at offset 0x6484 4696 bytes
font_02_sfnt_off00007131.bin
003210b7568e013750ddbe586b2b122fe398ef7522fb7016a759ac26459141cc
pdf-font-stream PDF embedded font (sfnt) at offset 0x7131 11532 bytes
font_03_sfnt_off000096eb.bin
a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f
pdf-font-stream PDF embedded font (sfnt) at offset 0x96EB 4324 bytes