Malicious PDF — malware analysis report

Static analysis result for SHA-256 5318ea83ea03ef64…

MALICIOUS

PDF

35.8 KB Created: 2020-08-03 21:01:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 40af210416ac7dcd37737b659dab0b56 SHA-1: 4f93d2e410a5647916937b2aa4e6969be5112d6d SHA-256: 5318ea83ea03ef64cd5e7a8841276ae19428e3cafa75fcf7eff29de9820d6ce9
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains numerous embedded links, a common tactic for SEO poisoning and redirecting users to malicious sites. One critical heuristic identified a link to a known malicious redirector, ttraff.cc, which is disguised as a chemistry textbook PDF. The document body, though heavily obfuscated, contains the same URL and references to chemistry textbooks, reinforcing the lure. The presence of multiple shopify.com links, while marked as benign, are part of a larger link farm strategy. The primary attack vector appears to be social engineering through a deceptive document.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=peter+atkins+principios+de+quimica+pdf
    • http://files.give60for60.org/uploads/1/3/1/8/131857120/de204f749c83.pdf
    • http://files.herbheathmusic.com/uploads/1/3/1/3/131380759/6917697.pdf
    • http://files.callidevalleyvet.com/uploads/1/3/1/4/131483281/wivotata.pdf
    • http://sokubi.walkingmeditation.eu/uploads/1/3/1/4/131452836/58bf743acc35f9.pdf
    • http://files.justingalushaphotography.com/uploads/1/3/2/7/132740329/jadubisejuneg_jonepirepapu.pdf
    • https://cdn.shopify.com/s/files/1/0432/8013/8398/files/dovebowunelukulepu.pdf
    • https://cdn.shopify.com/s/files/1/0428/3292/0732/files/49158112403.pdf
    • https://cdn.shopify.com/s/files/1/0439/4303/5048/files/princess_mononoke_soundtrack.pdf
    • https://cdn.shopify.com/s/files/1/0427/8996/1884/files/dugijal.pdf
    • https://cdn.shopify.com/s/files/1/0430/4008/0025/files/42586491611.pdf
    • https://cdn.shopify.com/s/files/1/0433/8037/5704/files/vuwovitapawagegarovaguvew.pdf
    • https://cdn.shopify.com/s/files/1/0429/6641/7571/files/somunabufawul.pdf
    • https://cdn.shopify.com/s/files/1/0432/9226/2560/files/26841716125.pdf
    • https://cdn.shopify.com/s/files/1/0434/6550/6966/files/72950374926.pdf
    • https://cdn.shopify.com/s/files/1/0433/1264/4251/files/dark_souls_2_whips.pdf
    • https://cdn.shopify.com/s/files/1/0433/3223/9528/files/zifuvefedaloxibe.pdf
    • https://cdn.shopify.com/s/files/1/0437/2158/8888/files/kikowezozuseviri.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004cfb.bin
2a0d3c0db10d6afd8d383f607412e687860a07e7d636e94075a1b126ebf97f91
pdf-font-stream PDF embedded font (sfnt) at offset 0x4CFB 5460 bytes
font_01_sfnt_off00005f7f.bin
b0d7253ded19dfd36fd7bd5da4fd9d21a011b4247dd8eb0be0706a0ebcf0d6e6
pdf-font-stream PDF embedded font (sfnt) at offset 0x5F7F 10060 bytes