Malicious PDF — malware analysis report

Static analysis result for SHA-256 b1d0633776d8a8ce…

MALICIOUS

PDF

45.5 KB Created: 2020-08-06 04:03:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 63f212fb9b82ae829d45e455c23af589 SHA-1: 6a1e1908ce3d3577c4cf526d8d2d6bc67d3ac85b SHA-256: b1d0633776d8a8ced5e8ba732a73dbcc233f836ec8f67b9648896b53ddf2b762
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=ibps+clerk+syllabus+pdf'. This URL is presented within the document body, suggesting a social engineering lure to trick users into downloading further content. The presence of numerous external PDF links, many hosted on Shopify, indicates a link farm strategy, likely to improve search engine ranking for deceptive content. No scripts were extracted, and the document body was heavily obfuscated, but the primary intent appears to be redirecting users to malicious sites.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=ibps+clerk+syllabus+pdf
    • http://files.embraceboudoir.com/uploads/1/3/2/8/132815828/7753716.pdf
    • http://files.alexanderskutch.com/uploads/1/3/1/4/131453810/9bc790dc56d283f.pdf
    • http://files.wallacepublishing.co.uk/uploads/1/3/1/3/131398010/02bf3d02b08823d.pdf
    • https://cdn.shopify.com/s/files/1/0436/3137/8590/files/94015135812.pdf
    • https://cdn.shopify.com/s/files/1/0437/9557/9029/files/cahier_de_vacances_gratuit_a_imprimer_5eme.pdf
    • https://cdn.shopify.com/s/files/1/0427/9920/2467/files/49950775514.pdf
    • https://cdn.shopify.com/s/files/1/0438/2644/6498/files/rorawulajokulidejugap.pdf
    • https://cdn.shopify.com/s/files/1/0432/4130/8320/files/pelisajulilo.pdf
    • https://cdn.shopify.com/s/files/1/0433/3128/9256/files/33608236574.pdf
    • https://cdn.shopify.com/s/files/1/0438/8388/8808/files/2282266176.pdf
    • https://cdn.shopify.com/s/files/1/0433/8699/4855/files/cr_4_monsters_5e.pdf
    • https://cdn.shopify.com/s/files/1/0438/0655/6322/files/hurt_nin_lyrics.pdf
    • https://cdn.shopify.com/s/files/1/0431/4267/6636/files/40598524798.pdf
    • https://cdn.shopify.com/s/files/1/0432/7551/8107/files/febukomeki.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000066d8.bin
c0a056cd8dd73e0a190ca9c72a244b274c55667303be431690bb4a785fca6b9b
pdf-font-stream PDF embedded font (sfnt) at offset 0x66D8 4932 bytes
font_01_sfnt_off000077a6.bin
4199230310b1adc175a7a5f065c38db2cf5c3cdab8f10df3bd863022b1474147
pdf-font-stream PDF embedded font (sfnt) at offset 0x77A6 10468 bytes
font_02_sfnt_off00009b3b.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0x9B3B 4324 bytes