Malicious PDF — malware analysis report

Static analysis result for SHA-256 85cf326c75277046…

MALICIOUS

PDF

48.5 KB Created: 2020-08-10 00:45:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4b7d853f3beb65cb26a15980f7b0f9ec SHA-1: 07c9ae0a6633bd0c302799127cba923fa0abee35 SHA-256: 85cf326c7527704661b34c1c012a3eadb6e4bddbf1ef42a3e2df78944cbcdc75
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, many of which point to external PDFs hosted on various domains. One critical heuristic identified a link to a known malicious redirector, ttraff.cc, which is likely used to obscure the final malicious destination. The document body text, though partially corrupted, contains the phrase 'B. com syllabus 2nd year pdf', suggesting a lure to academic or informational content. The presence of numerous links, including one to a malicious redirector, indicates an attempt to drive traffic to potentially harmful sites.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=b.+com+syllabus+2nd+year+pdf
    • http://popad.ralieducator.com/uploads/1/3/1/3/131398140/lazom.pdf
    • http://files.m-d.systems/uploads/1/3/0/7/130739232/ketibopesezaxa_nilipopigoreniz.pdf
    • http://files.lottamoberg.com/uploads/1/3/0/9/130968931/vokuwimikavu.pdf
    • https://cdn.shopify.com/s/files/1/0434/0636/0725/files/pigutajovajoxivodazuluje.pdf
    • https://cdn.shopify.com/s/files/1/0436/0398/4547/files/res_aaResources._dll_104.pdf
    • https://cdn.shopify.com/s/files/1/0437/4151/1834/files/vewevofidubotigidizupus.pdf
    • https://cdn.shopify.com/s/files/1/0436/9347/3947/files/86897034841.pdf
    • https://cdn.shopify.com/s/files/1/0434/7274/8710/files/6641483946.pdf
    • https://cdn.shopify.com/s/files/1/0436/0133/0339/files/vefojorekebu.pdf
    • https://cdn.shopify.com/s/files/1/0431/1266/1152/files/potetaxases.pdf
    • https://cdn.shopify.com/s/files/1/0436/6077/1481/files/2020_australian_calendar.pdf
    • https://cdn.shopify.com/s/files/1/0438/0000/2717/files/biotecnologa_en_la_industria_y_agricultura.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/52665001447.pdf
    • https://cdn.shopify.com/s/files/1/0431/8396/4324/files/84521498520.pdf
    • https://cdn.shopify.com/s/files/1/0434/8536/4390/files/10013190091.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005edd.bin
01e65a9297b9bd9795f239439c2650520b8e2f18121b35a21e71430eb9469bca
pdf-font-stream PDF embedded font (sfnt) at offset 0x5EDD 5756 bytes
font_01_sfnt_off00007267.bin
d97e055e11de589539a249dfdf9c15aca1e9caf4700104d1763a3a5d87d8f7f2
pdf-font-stream PDF embedded font (sfnt) at offset 0x7267 2320 bytes
font_02_sfnt_off00007cb9.bin
cb50431fc1ee656f20f4d4a649f2f0dab163924533e46684e26677ccb1d189fe
pdf-font-stream PDF embedded font (sfnt) at offset 0x7CB9 10068 bytes
font_03_sfnt_off00009f37.bin
207faf14306426b668b87aba0c9d447b8ba40b67f0f7b18660ffa0d3c8132265
pdf-font-stream PDF embedded font (sfnt) at offset 0x9F37 16224 bytes