Malicious PDF — malware analysis report

Static analysis result for SHA-256 b9b0845259b01ad9…

MALICIOUS

PDF

70.8 KB Created: 2020-10-17 01:52:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 95eeffea148808a64f20f3f6b642bb55 SHA-1: ac3b3faf1bc1cc7650ce29feb7a6a346a43c7c40 SHA-256: b9b0845259b01ad92d7f8fd8a7c06df8ef03f9c5e6cdab34cb8b58b4852baca6
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, many of which point to a link farm hosted on weebly.com and strikinglycdn.com. One critical heuristic firing indicates that the PDF links to known malicious redirector infrastructure at 'https://ttraff.club/123?keyword=definition+of+community+engagement+pdf'. This suggests the document is designed to redirect users to malicious sites, likely for phishing or malware distribution.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/123?keyword=definition+of+community+engagement+pdf
    • https://fusesekomufe.weebly.com/uploads/1/3/1/6/131606177/lamexero.pdf
    • https://mixorone.weebly.com/uploads/1/3/1/4/131438240/5368771.pdf
    • https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/lamelofupulese_vufisizomapurus.pdf
    • https://sovopubi.weebly.com/uploads/1/3/0/7/130775052/7963849.pdf
    • https://cdn-cms.f-static.net/uploads/4366017/normal_5f86fbc9b919b.pdf
    • https://cdn-cms.f-static.net/uploads/4366664/normal_5f8748eea81f9.pdf
    • https://cdn-cms.f-static.net/uploads/4365586/normal_5f87f60927674.pdf
    • https://cdn-cms.f-static.net/uploads/4376372/normal_5f89a94cac8c9.pdf
    • https://xojerajap.weebly.com/uploads/1/3/1/3/131384359/foburadip.pdf
    • https://boguvetasitob.weebly.com/uploads/1/3/1/3/131380850/pifojefas_jibanuporo_lajukasug.pdf
    • https://lodirunesu.weebly.com/uploads/1/3/0/8/130874391/d549da259ed0cb.pdf
    • https://fifowekuvepu.weebly.com/uploads/1/3/0/7/130776735/47a91673.pdf
    • https://xojisige.weebly.com/uploads/1/3/1/6/131637148/zemokivajuf.pdf
    • https://uploads.strikinglycdn.com/files/cfbeec13-d076-42f3-b8ac-89734ae6f2cf/lajakopugarupigubanos.pdf
    • https://uploads.strikinglycdn.com/files/01fe040a-d8ba-4e8d-9672-5a527fce77ee/luxafubadezumilivemakiwu.pdf
    • https://uploads.strikinglycdn.com/files/b38ad325-63f2-49c0-ace7-3befadb6b00e/dojabi.pdf
    • https://uploads.strikinglycdn.com/files/0c064e61-86fc-484d-b581-e0edad1ed9fc/76717113392.pdf
    • https://uploads.strikinglycdn.com/files/00537739-6a27-4574-89c4-85fc8c3c95f8/patedifipatorisifajedume.pdf
    • https://uploads.strikinglycdn.com/files/7c7299c2-4d1e-4916-a848-d442ca6b6f3c/86282902158.pdf
    • https://uploads.strikinglycdn.com/files/94966dec-1513-40e4-a063-a1400ed8a5c2/suwufaverogabi.pdf
    • https://uploads.strikinglycdn.com/files/b4ea9a21-996f-4ae2-8c73-28f8db69c367/wafifebonojotiv.pdf
    • https://uploads.strikinglycdn.com/files/ebbd613a-c35a-4d6b-a2ff-24f95aa73498/nanexu.pdf
    • https://uploads.strikinglycdn.com/files/1a0373f5-b4af-457e-a542-25b07b263870/4595567655.pdf
    • https://uploads.strikinglycdn.com/files/ae6d2afb-f3f7-4377-b0b1-eb0d5820a8d9/sikifo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d880.bin
a92cd5b6a7c1f441efa46f462717ffd7eec28b16d66ea08d1de9602443252dcd
pdf-font-stream PDF embedded font (sfnt) at offset 0xD880 5272 bytes
font_01_sfnt_off0000ea70.bin
8b3567de68f8a565ac16e7b16b436b0c5f03864826065df71fd1879375cf2f82
pdf-font-stream PDF embedded font (sfnt) at offset 0xEA70 10296 bytes