Malicious PDF — malware analysis report

Static analysis result for SHA-256 59bf8ca844d011a8…

MALICIOUS

PDF

33.7 KB Created: 2020-08-12 04:49:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6cd4e3cbd55a909df271fd9d87a3832c SHA-1: 5bdc02452fc97f38d0eb57729e1f331f7b4d6e15 SHA-256: 59bf8ca844d011a80c763a0de522b8241361ec6495ca36ede3a115909805210e
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded links, many of which point to a redirector service (ttraff.com) known to host malicious content. The document body, though heavily obfuscated, also contains the same redirector URL and numerous other links hosted on cdn.shopify.com and other domains, suggesting a link farm or SEO poisoning tactic to distribute malicious payloads. No scripts were extracted, but the primary attack vector appears to be social engineering via deceptive links.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wb?keyword=soil%20horizons%20diagram%20worksheet
    • http://files.charaliliana.com/uploads/1/3/0/8/130874539/jetovete.pdf
    • http://nusadazel.rachelvphoto.com/uploads/1/3/0/8/130814328/9f020011e.pdf
    • http://files.dianahubbell.com/uploads/1/3/2/6/132683154/povijetul-bitatizepenawov-xubupabixifo.pdf
    • http://files.silverspur.com/uploads/1/3/0/7/130739393/futuvevaradonu_zesiw_vufuni_damivokit.pdf
    • http://files.markeedamclean.com/uploads/1/3/1/3/131380308/madufo.pdf
    • https://cdn.shopify.com/s/files/1/0438/1822/1730/files/78702899414.pdf
    • https://cdn.shopify.com/s/files/1/0440/6863/4789/files/crazy_monday.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/44219577828.pdf
    • https://cdn.shopify.com/s/files/1/0433/5285/0586/files/54397431273.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/baxumedufimoval.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/69296453687.pdf
    • https://cdn.shopify.com/s/files/1/0435/4539/5368/files/wotomikefafawotabin.pdf
    • https://cdn.shopify.com/s/files/1/0429/0910/6335/files/minecraft_tp_to_player.pdf
    • https://cdn.shopify.com/s/files/1/0434/9535/8624/files/anthony_giddens_sociology_book.pdf
    • https://cdn.shopify.com/s/files/1/0437/3735/0309/files/xurabexuvusufajutez.pdf
    • https://cdn.shopify.com/s/files/1/0431/1423/4017/files/31989180196.pdf
    • https://cdn.shopify.com/s/files/1/0435/8799/3763/files/change_scroll_direction_windows_10.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000470b.bin
359252c3b2efde32cb2990adae36cf8795c1b9dda46e1b262451cb0337777678
pdf-font-stream PDF embedded font (sfnt) at offset 0x470B 5548 bytes
font_01_sfnt_off000059c8.bin
75f21988b758d2365a1bb93ff14b46ecb6a609e0db70e8ba490607200126234c
pdf-font-stream PDF embedded font (sfnt) at offset 0x59C8 9412 bytes