Malicious PDF — malware analysis report

Static analysis result for SHA-256 9424dc983e531ad1…

MALICIOUS

PDF

40.6 KB Created: 2020-08-10 05:04:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 623137e5af56a1b062b983ff97453b35 SHA-1: 934f00b6d892bba64e496de30756dcde1482dfcb SHA-256: 9424dc983e531ad1afd98ad4b337ce351a05b267603a78369e7748b78413910f
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a link farm and a malicious redirector. The primary link, https://ttraff.com/pify?keyword=calabozos+y+dragones+manual+de+monstruos+pdf, is designed to lure users into clicking by appearing to offer a desirable PDF. This link then redirects to other URLs, some of which are benign Shopify links, but the initial redirector is flagged as malicious. No scripts were extracted, and the document body is heavily obfuscated, but the presence of the malicious redirector and link farm strongly indicates a phishing or malware distribution attempt.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=calabozos+y+dragones+manual+de+monstruos+pdf
    • http://files.cyniccritiq.com/uploads/1/3/1/4/131454523/zovuximezepo-sexudutufuku.pdf
    • http://nupaxewix.aroundtheworldin800days.com/uploads/1/3/2/6/132696111/rotoweser_wukezixifupev_wufikixekapu.pdf
    • http://files.aaadentalbahamas.com/uploads/1/3/1/3/131384340/b484aac553bf5.pdf
    • http://files.southeugenemusic.org/uploads/1/3/0/8/130873921/2300842.pdf
    • http://pogopaj.ivepriest.org/uploads/1/3/0/9/130969723/mowavivuvuk_fugubakuwesomor_wapakuzuz.pdf
    • https://cdn.shopify.com/s/files/1/0433/2604/6362/files/vigojepe.pdf
    • https://cdn.shopify.com/s/files/1/0432/5395/6766/files/2815236243.pdf
    • https://cdn.shopify.com/s/files/1/0431/1390/6327/files/tatafomebibinopodogus.pdf
    • https://cdn.shopify.com/s/files/1/0434/7595/9973/files/77659455966.pdf
    • https://cdn.shopify.com/s/files/1/0440/1741/8405/files/ready_player_one_book.pdf
    • https://cdn.shopify.com/s/files/1/0429/9807/1450/files/nonexav.pdf
    • https://cdn.shopify.com/s/files/1/0437/0087/9510/files/34886983434.pdf
    • https://cdn.shopify.com/s/files/1/0429/6297/6921/files/9647493868.pdf
    • https://cdn.shopify.com/s/files/1/0431/4834/5500/files/30789706404.pdf
    • https://cdn.shopify.com/s/files/1/0432/8990/3259/files/rolilosifumifavelijub.pdf
    • https://cdn.shopify.com/s/files/1/0430/6750/6849/files/kubivutafogi.pdf
    • https://cdn.shopify.com/s/files/1/0434/0740/9308/files/supper_video_converter.pdf
    • https://cdn.shopify.com/s/files/1/0435/2871/6439/files/81729138586.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005b60.bin
1d7bd75eedb212c2c12578a8dd624e416601b90ccddfb68b8d8f5228f16db7dd
pdf-font-stream PDF embedded font (sfnt) at offset 0x5B60 5556 bytes
font_01_sfnt_off00006e34.bin
670229b5d485e44e47ef65f352e030a8a513243d2150790cd39d46847ba808ee
pdf-font-stream PDF embedded font (sfnt) at offset 0x6E34 11744 bytes