Malicious PDF — malware analysis report

Static analysis result for SHA-256 944c079dc0d5c1db…

MALICIOUS

PDF

85.3 KB Created: 2020-08-01 17:01:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5f447171b2f5924eeae64b2ef23cf494 SHA-1: 397cacc8c386b25ad415e56759f37f80dbd959fe SHA-256: 944c079dc0d5c1db648a2af83075a11f76f89fbc70b5e39a16390db4e7c49e36
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=cbspd+technician+study+guide'. This indicates the document's primary purpose is to redirect the user to a malicious site. Additionally, a PDF link farm heuristic suggests a large number of outbound links, likely for SEO poisoning or to obscure the malicious destination. The document body contains garbled text but also includes the malicious URL, reinforcing the attack vector.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=cbspd+technician+study+guide
    • http://files.brightonfd.com/uploads/1/3/0/8/130874691/zidunakixer-nuzewinubopu.pdf
    • http://files.bullochhallquiltguild.org/uploads/1/3/2/7/132741241/9193050.pdf
    • http://files.returntoyourself.org/uploads/1/3/1/4/131453855/loruxutitutilomepuso.pdf
    • http://files.bandenservice4u.nl/uploads/1/3/1/8/131872178/pirixovatid.pdf
    • http://files.brushcreekcreamery.com/uploads/1/3/1/3/131384401/4953916.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/40035930655.pdf
    • https://cdn.shopify.com/s/files/1/0440/5254/5701/files/39666472630.pdf
    • https://cdn.shopify.com/s/files/1/0431/1983/7345/files/didimokebugobalibinixibed.pdf
    • https://cdn.shopify.com/s/files/1/0432/0700/0219/files/xatomiwirirorivuwotid.pdf
    • https://cdn.shopify.com/s/files/1/0431/7852/4831/files/heathkit_hw-_101.pdf
    • https://cdn.shopify.com/s/files/1/0430/8038/4674/files/53754772239.pdf
    • https://cdn.shopify.com/s/files/1/0436/3531/0752/files/47699580657.pdf
    • https://cdn.shopify.com/s/files/1/0430/9201/7305/files/89597871002.pdf
    • https://cdn.shopify.com/s/files/1/0430/0177/4233/files/bevil.pdf
    • https://cdn.shopify.com/s/files/1/0434/0318/2231/files/1000_largest_cities_in_the_us.pdf
    • https://cdn.shopify.com/s/files/1/0434/4945/0661/files/rutowu.pdf
    • https://cdn.shopify.com/s/files/1/0434/0006/9285/files/63249157620.pdf
    • https://cdn.shopify.com/s/files/1/0438/4233/8981/files/fopevat.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00010432.bin
97dea03ca01e93ad1af0e48b6e76fba6dbe44bc4c2c4ce742f419008ae95b12a
pdf-font-stream PDF embedded font (sfnt) at offset 0x10432 5356 bytes
font_01_sfnt_off00011664.bin
e294282028a5aead02d5ddf0e2e847aafd7a5ea7fec471cd17e2ee9308c13f1d
pdf-font-stream PDF embedded font (sfnt) at offset 0x11664 16136 bytes