Malicious PDF — malware analysis report

Static analysis result for SHA-256 a81ba0d37c21abdd…

MALICIOUS

PDF

126.9 KB Created: 2020-08-20 03:16:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4f9865291e9567ccd7d70d1c3d8dac0b SHA-1: 193fa73dcd90071457ad9bdad996e0e37bcb0823 SHA-256: a81ba0d37c21abdd66e1bde90f1e33c176a5c949ca522e1b1f43343db3356ba1
160 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://ttraff.ru/pify?keyword=tchibo+cafissimo+tuttocaff%25C3%25A8+saeco+manual'. Additionally, a high severity heuristic indicates visible LOLBin command execution instructions within the document. The document body, though heavily obfuscated, also contains the same malicious URL. These factors suggest the primary intent is to lure the user to a malicious site.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visible LOLBin command execution instruction high SE_LOLBIN_RUN_COMMAND
    Document contains instructions or visible command text involving Windows script/execution tools such as PowerShell, mshta, cmd, rundll32, or regsvr32
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=tchibo+cafissimo+tuttocaff%25C3%25A8+saeco+manual
    • http://files.letsbuytoys.shop/uploads/1/3/0/8/130813906/reximovi_rokozeg.pdf
    • http://files.rongoodine.com/uploads/1/3/0/7/130739674/posazupijevuvet-luwivoluwala-madilos-sobavozabe.pdf
    • http://nebad.nonohairremoval202.greatwebsitebuilder.com/uploads/1/3/1/3/131383657/9ff27255cd5f106.pdf
    • https://cdn.shopify.com/s/files/1/0430/9506/4730/files/nufuxunarejol.pdf
    • https://cdn.shopify.com/s/files/1/0429/1241/5907/files/34163560540.pdf
    • https://cdn.shopify.com/s/files/1/0428/1368/5927/files/43109829175.pdf
    • https://cdn.shopify.com/s/files/1/0429/9161/6153/files/management_of_breast_abscess.pdf
    • https://cdn.shopify.com/s/files/1/0429/6025/7177/files/44874614619.pdf
    • https://cdn.shopify.com/s/files/1/0431/4991/8374/files/79252842903.pdf
    • https://cdn.shopify.com/s/files/1/0428/1883/0492/files/74153577347.pdf
    • https://cdn.shopify.com/s/files/1/0437/8145/6023/files/wget_from_github.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/76106621034.pdf
    • https://cdn.shopify.com/s/files/1/0434/8562/6520/files/xujafozavalekabanivaji.pdf
    • https://cdn.shopify.com/s/files/1/0435/5964/9429/files/bariwosozosiva.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00017b4c.bin
1c8600ad1e317a47208cd17b62fc50793aa8106a26494dcf008d8bdb8e39b24c
pdf-font-stream PDF embedded font (sfnt) at offset 0x17B4C 9164 bytes
font_01_sfnt_off000199f9.bin
cc5f89d2c94ef1180b0088e5450e6021e388c290792a4293c550a6a4b31d069b
pdf-font-stream PDF embedded font (sfnt) at offset 0x199F9 5256 bytes
font_02_sfnt_off0001ab75.bin
c97ce0be5f4a9aeb0bfbc5fb6b5a826e64323839501384816a9ea2b034624a80
pdf-font-stream PDF embedded font (sfnt) at offset 0x1AB75 12664 bytes
font_03_sfnt_off0001d45b.bin
f3e02129bff4cbbc934b01e18f431f77722967162bacd7e1c6c07dada7d1acfe
pdf-font-stream PDF embedded font (sfnt) at offset 0x1D45B 16512 bytes