Malicious PDF — malware analysis report

Static analysis result for SHA-256 83732a50be9cf78e…

MALICIOUS

PDF

46.6 KB Created: 2020-08-24 05:00:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7b981dcf5bef954d95c4d0f768caadbd SHA-1: 73972d4dff895ececec3be87e210b72eacefe5fa SHA-256: 83732a50be9cf78e4b5da2c9b13785f47ea641e3ec2a5b95e6add2aa2d00dc0b
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, many of which point to external resources, indicating a link farm. One of the primary URLs, 'https://ttraff.com/pify?keyword=calisthenics+app+android', is flagged as a malicious redirector. The document body, though heavily obfuscated, also contains this URL, suggesting the intent is to lure the user to malicious infrastructure. No scripts were extracted, limiting the analysis of direct execution capabilities.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=calisthenics+app+android
    • http://zofowav.lindsborgadhocroundtable.com/uploads/1/3/1/4/131438324/5689251.pdf
    • http://files.nimatennis.com.au/uploads/1/3/1/6/131606965/4116325.pdf
    • http://files.learnguitar4fun.com/uploads/1/3/1/8/131856381/8522082.pdf
    • http://files.tony-medina.com/uploads/1/3/0/7/130776123/defagexeve-sifibur-roxojixawo.pdf
    • http://files.argumentationtoolkit.org/uploads/1/3/0/7/130739396/xoruboj-xutodin.pdf
    • https://cdn.shopify.com/s/files/1/0432/0041/3856/files/vutorudifadeguzugux.pdf
    • https://cdn.shopify.com/s/files/1/0434/9722/6402/files/curriculum_vitae_online_gratis.pdf
    • https://cdn.shopify.com/s/files/1/0440/3786/5637/files/76637846847.pdf
    • https://cdn.shopify.com/s/files/1/0432/5244/9435/files/53655279192.pdf
    • https://cdn.shopify.com/s/files/1/0430/3480/4375/files/74223918954.pdf
    • https://cdn.shopify.com/s/files/1/0439/1400/2600/files/98567955441.pdf
    • https://cdn.shopify.com/s/files/1/0429/1582/3772/files/gakisuzegalonaje.pdf
    • https://cdn.shopify.com/s/files/1/0431/6112/5015/files/lalanorujavabe.pdf
    • https://cdn.shopify.com/s/files/1/0428/2767/7852/files/xipedutozilukanepisop.pdf
    • https://cdn.shopify.com/s/files/1/0432/0926/1217/files/theory_of_metal_forming_notes.pdf
    • https://cdn.shopify.com/s/files/1/0431/1754/3588/files/final_written_warning_template_acas.pdf
    • https://cdn.shopify.com/s/files/1/0432/5064/7204/files/82192502900.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006c88.bin
3d71cc6f8b236be7903c67761b9c55c97244fb6a70a71f5d56e759a3154e874a
pdf-font-stream PDF embedded font (sfnt) at offset 0x6C88 4972 bytes
font_01_sfnt_off00007d4d.bin
76c71d6151f4775247015072c600e776729fb214e4f4ac1420195bb8547b07a2
pdf-font-stream PDF embedded font (sfnt) at offset 0x7D4D 9992 bytes
font_02_sfnt_off00009f7d.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0x9F7D 4324 bytes