Malicious PDF — malware analysis report

Static analysis result for SHA-256 93c7b8e2646a2d9c…

MALICIOUS

PDF

53.1 KB Created: 2020-09-02 21:18:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 471a2bd06d56af823978074cefec3d84 SHA-1: 26dd2ee091731f795ee86c9dcb15e9b4a1b11375 SHA-256: 93c7b8e2646a2d9c2538f1679f458c5ce91beb5cd378e49c90d5db9341809d10
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for PDF_MALICIOUS_REDIRECTOR_LINK, indicating it directs users to malicious infrastructure. The embedded link, presented as "Core java basics notes pdf", resolves to `https://ttraff.com/wix?keyword=core+java+basics+notes+pdf`. This URL is likely part of a phishing or scam campaign designed to trick users into visiting a compromised or malicious website. The PDF also exhibits characteristics of a link farm, with numerous external links, suggesting an attempt to manipulate search engine results or distribute traffic to various sites.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=core+java+basics+notes+pdf
    • https://static.usrfiles.com/ugd/1fa6dd_dfbe95d837114b7cb258bf33042d5eb3.pdf
    • https://static.usrfiles.com/ugd/b52961_539ab6c7627e4814a510f71c4a65a62b.pdf
    • https://static.usrfiles.com/ugd/b8c837_875461cfcc4b485691aa70b021992d2b.pdf
    • https://static.usrfiles.com/ugd/e3ed1f_9cd3dafe50824caf8979ace6356fa9c6.pdf
    • https://static.usrfiles.com/ugd/89363e_eeab9efe986544dfb250bf4f8ee5515e.pdf
    • https://static.usrfiles.com/ugd/5b5da7_c5f96984d45a44479f9f5a95f4ad6cb6.pdf
    • https://static.usrfiles.com/ugd/b8c837_e268caaef2da41fcadac0c154334b4f2.pdf
    • https://static.usrfiles.com/ugd/e4ee87_16d58bda222c4a0c89a49d595a2f9699.pdf
    • https://cdn.shopify.com/s/files/1/0462/3692/6112/files/absorbancia_y_transmitancia_infrarrojo.pdf
    • https://cdn.shopify.com/s/files/1/0430/0885/2117/files/wopafikivetava.pdf
    • https://cdn.shopify.com/s/files/1/0429/1608/5916/files/aladdin_complete_series.pdf
    • https://cdn.shopify.com/s/files/1/0435/4395/3563/files/kirby_table_flip.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000061a5.bin
a4af041a1f0d4c38f6ad1bf96ad04d86226b7158e00c36bfafa620d2932d04d4
pdf-font-stream PDF embedded font (sfnt) at offset 0x61A5 6568 bytes
font_01_sfnt_off000071f3.bin
6afc721c1ef40e4d5428176c59e2b8166c8370d50ce02aef1201c0ee8446c54b
pdf-font-stream PDF embedded font (sfnt) at offset 0x71F3 5296 bytes
font_02_sfnt_off00008401.bin
559e339ebb012a4711299e9f436f2accabb026881398d3942dea161b76ad44a3
pdf-font-stream PDF embedded font (sfnt) at offset 0x8401 1804 bytes
font_03_sfnt_off00008cdf.bin
a4f559ab57482ce04aa7332a0181cd5f39fcdf9adf61f1dd63132c7f99d11f9b
pdf-font-stream PDF embedded font (sfnt) at offset 0x8CDF 10576 bytes
font_04_sfnt_off0000b108.bin
51babe3b44e703ca5a92278b053c112c5c116674d3b708c8e2cb3e4aa6bd9a04
pdf-font-stream PDF embedded font (sfnt) at offset 0xB108 16148 bytes