Malicious PDF — malware analysis report

Static analysis result for SHA-256 81f0544247a33d37…

MALICIOUS

PDF

48.1 KB Created: 2020-07-28 06:48:30 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 58b39a6eef2052adfc62d8719e239738 SHA-1: 9c68af45baf718bd498544609e2d0e116439a47f SHA-256: 81f0544247a33d37b671c56bcb67c66df83a8550eed74441fd47fd67d8399f40
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains numerous embedded links, with a critical heuristic firing indicating a link to a known malicious redirector at 'ttraff.com'. The document body, though heavily corrupted, suggests a lure related to economic systems ('capitalismo socialismo e comunismo pdf'). The presence of a link farm heuristic further supports the malicious intent of distributing traffic to potentially harmful sites.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=diferen%25C3%25A7a+entre+capitalismo+socialismo+e+comunismo+pdf
    • http://files.pacificbuildersintl.com/uploads/1/3/1/4/131407135/nelamadakusuruf.pdf
    • http://files.absolutelyradiantphotography.com/uploads/1/3/0/7/130776295/332ac6b6c5.pdf
    • http://files.stillmomentsbycarmen.com/uploads/1/3/1/0/131069763/f4dacac602c0b11.pdf
    • http://files.kippste.org/uploads/1/3/1/3/131384436/99988fca9d.pdf
    • http://files.warriorartsacademy.net/uploads/1/3/2/7/132710787/bb174738b257d8.pdf
    • https://cdn.shopify.com/s/files/1/0436/1243/8685/files/rosoluvu.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/fuwofomakilaxenifotet.pdf
    • https://cdn.shopify.com/s/files/1/0436/0414/8381/files/13035695190.pdf
    • https://cdn.shopify.com/s/files/1/0433/2093/4558/files/92990866953.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/26450283228.pdf
    • https://cdn.shopify.com/s/files/1/0437/5887/8872/files/92298247288.pdf
    • https://cdn.shopify.com/s/files/1/0430/2936/4889/files/24614388090.pdf
    • https://cdn.shopify.com/s/files/1/0435/6787/4207/files/76492879390.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/sejil.pdf
    • https://cdn.shopify.com/s/files/1/0427/6797/4556/files/37698775041.pdf
    • https://cdn.shopify.com/s/files/1/0434/0131/4456/files/83419074968.pdf
    • https://cdn.shopify.com/s/files/1/0437/1054/6070/files/xupazomimoboxenusemab.pdf
    • https://cdn.shopify.com/s/files/1/0434/6265/6157/files/45179095617.pdf
    • https://cdn.shopify.com/s/files/1/0430/5721/7693/files/sakipivuduwu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007a2c.bin
42d95abfb4940b52b936a36f6c0c2a5ed48fec1b9a147ce3069c7a90cd476852
pdf-font-stream PDF embedded font (sfnt) at offset 0x7A2C 5364 bytes
font_01_sfnt_off00008c09.bin
9e7a9264bc9cbfed4d7d1a7680d660f6bf1743b0ba8fac95fe650eea84a78880
pdf-font-stream PDF embedded font (sfnt) at offset 0x8C09 11888 bytes