Malicious PDF — malware analysis report

Static analysis result for SHA-256 74d5dc5fa4c499e2…

MALICIOUS

PDF

54.1 KB Created: 2020-08-03 02:05:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 758f705c66910238e411ce561f0d905b SHA-1: 775d8d52020fa9ecf80f76fce662b8d95f750c73 SHA-256: 74d5dc5fa4c499e22d2192e6ce7f56d5826fcbf3cc16fca4a8aea03b76f8951e
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link to a known malicious redirector, ttraff.cc, which is designed to lure users to malicious sites. The document body, though partially corrupted, contains the text 'How to extend centos root partition' and the malicious URL, suggesting a social engineering pretext. The PDF also contains a large number of external links, many hosted on Shopify, which is characteristic of SEO link farm abuse.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=how+to+extend+centos+root+partition
    • http://files.thefeatherednestdowntownwestjefferson.com/uploads/1/3/1/3/131382113/2964567.pdf
    • http://files.kristinmize.com/uploads/1/3/1/3/131383045/0383bb.pdf
    • http://files.nectrathletics.com/uploads/1/3/1/4/131455832/2461608.pdf
    • http://files.nationalparks-list.com/uploads/1/3/1/6/131606069/7689536.pdf
    • https://cdn.shopify.com/s/files/1/0431/2704/6301/files/85307505043.pdf
    • https://cdn.shopify.com/s/files/1/0437/1821/3797/files/gomelofogoxuwop.pdf
    • https://cdn.shopify.com/s/files/1/0431/9808/7328/files/97172403468.pdf
    • https://cdn.shopify.com/s/files/1/0429/9220/5978/files/90685543867.pdf
    • https://cdn.shopify.com/s/files/1/0431/9058/3458/files/33910608003.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/buxidumex.pdf
    • https://cdn.shopify.com/s/files/1/0436/7374/7609/files/lekotevirul.pdf
    • https://cdn.shopify.com/s/files/1/0430/8844/5604/files/balugokibasaf.pdf
    • https://cdn.shopify.com/s/files/1/0434/1802/6142/files/7949663993.pdf
    • https://cdn.shopify.com/s/files/1/0431/9094/3904/files/43781313117.pdf
    • https://cdn.shopify.com/s/files/1/0431/8347/2802/files/76351455210.pdf
    • https://cdn.shopify.com/s/files/1/0435/2222/8379/files/dodamovadez.pdf
    • https://cdn.shopify.com/s/files/1/0433/4744/3865/files/36377081960.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007412.bin
be0dcac99846fde195b65d47d1d53bf9a97392a57a7795d38f798964ad418865
pdf-font-stream PDF embedded font (sfnt) at offset 0x7412 5156 bytes
font_01_sfnt_off000085b4.bin
cfce45d21a7a9d182e8773ee9a4ad8a11b20216d39b59de4b49796c6210b1b2a
pdf-font-stream PDF embedded font (sfnt) at offset 0x85B4 2788 bytes
font_02_sfnt_off000091d4.bin
2ab153617b1863e59a81f6d98f9100f28b578711f02c05282233fc1ca7ee1b69
pdf-font-stream PDF embedded font (sfnt) at offset 0x91D4 10404 bytes
font_03_sfnt_off0000b5ab.bin
52db30b66cfb76898988bc7c6ed152514c301740808ab95bec9c68e49df23550
pdf-font-stream PDF embedded font (sfnt) at offset 0xB5AB 16036 bytes