Malicious PDF — malware analysis report

Static analysis result for SHA-256 7bfbe3e94eefe705…

MALICIOUS

PDF

69.2 KB Created: 2020-08-09 06:07:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 84b9dca860aa3e1f827d7f08f8810c32 SHA-1: a84a65d0103761071ec68aa1ed33f67ec9bfccdc SHA-256: 7bfbe3e94eefe7053161c8b7e19f54ea8fc0a4e9bd7d6a8f3b530062510de3d0
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. It also exhibits characteristics of a PDF link farm, with numerous links hosted on Shopify domains, though most of these appear benign. The presence of a 'LOLBin run command' heuristic suggests the document may contain instructions or embedded commands for execution, likely related to leveraging the malicious URL. The document body itself is heavily obfuscated but contains the malicious URL.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visible LOLBin command execution instruction high SE_LOLBIN_RUN_COMMAND
    Document contains instructions or visible command text involving Windows script/execution tools such as PowerShell, mshta, cmd, rundll32, or regsvr32
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=augusto+c%25C3%25A9sar+sandino+pdf
    • http://netetem.friendsofmaduraiseed.org/uploads/1/3/1/4/131407406/5287505.pdf
    • http://files.joy-of-syntax.com/uploads/1/3/1/8/131857334/9739071.pdf
    • http://files.sacredspace-yoga.com/uploads/1/3/1/6/131637168/vivitevagesal-vigibefure-xifobozibalamok.pdf
    • http://files.gypsies77.com/uploads/1/3/2/7/132740277/23a5c79e41.pdf
    • https://cdn.shopify.com/s/files/1/0437/0386/1416/files/21592064046.pdf
    • https://cdn.shopify.com/s/files/1/0433/1126/7990/files/74623008438.pdf
    • https://cdn.shopify.com/s/files/1/0436/4114/3454/files/tobegijuvurefunigewize.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/3215656586.pdf
    • https://cdn.shopify.com/s/files/1/0434/4047/2214/files/sezotosumexer.pdf
    • https://cdn.shopify.com/s/files/1/0428/6690/1148/files/jujorolekevawegisafafa.pdf
    • https://cdn.shopify.com/s/files/1/0433/4642/8059/files/9930512005.pdf
    • https://cdn.shopify.com/s/files/1/0431/1197/3026/files/30407479905.pdf
    • https://cdn.shopify.com/s/files/1/0428/4396/3548/files/58289181199.pdf
    • https://cdn.shopify.com/s/files/1/0430/6888/3098/files/biodiesel_business_plan.pdf
    • https://cdn.shopify.com/s/files/1/0435/2737/2964/files/dr_all_terrain_mower.pdf
    • https://cdn.shopify.com/s/files/1/0437/9112/2584/files/50771695074.pdf
    • https://cdn.shopify.com/s/files/1/0431/0273/2448/files/powershell_change_password.pdf
    • https://cdn.shopify.com/s/files/1/0435/6096/0159/files/best_tablet_for_storing_and_readings.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000cdcd.bin
504f0be5f62d89ecdffdb970abad823ce75e512ec1aa67be4679979e5fc63abc
pdf-font-stream PDF embedded font (sfnt) at offset 0xCDCD 5420 bytes
font_01_sfnt_off0000e00f.bin
e4ddcd3f061bd8f26093c5b9cb80bfe13fa1fe4a4c11f2b50502394232c4dc33
pdf-font-stream PDF embedded font (sfnt) at offset 0xE00F 11444 bytes