Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba6421638c120813…

MALICIOUS

PDF

60.7 KB Created: 2020-08-17 14:03:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3b26f02bbbeb95b5f1554e363082cec5 SHA-1: ba73ae595e5d36daf2d61030bb768eda0be781da SHA-256: ba6421638c120813339fcae9f73e66e2f1a56eb8a1d9fd374417c9fee8febf6c
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=satie+gymnopedies+sheet+music'. Additionally, it exhibits characteristics of a PDF link farm, with numerous links to external PDFs, many hosted on Shopify. The document body, though partially corrupted, contains text related to 'Satie gymnopedies sheet music' and the wkhtmltopdf tool, suggesting a lure to disguise the malicious intent. The primary malicious IOC is the redirector URL, which is likely used to serve a secondary payload.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=satie+gymnopedies+sheet+music
    • http://files.leisaoart.com/uploads/1/3/0/9/130969850/xegesurebunilux-faronikinu-vabuvasedavaxan-modiv.pdf
    • http://jinune.stickystripz.com/uploads/1/3/1/4/131406717/5296885.pdf
    • http://kelopa.wakeforestfarmersmarket.com/uploads/1/3/2/6/132681670/0221112.pdf
    • http://files.valuetrainsusa.com/uploads/1/3/2/7/132741144/nopeja-pukanizepubajo.pdf
    • http://files.alpacapines.com/uploads/1/3/1/4/131483154/tazujoda.pdf
    • https://cdn.shopify.com/s/files/1/0432/1165/3282/files/zolakapunedepemis.pdf
    • https://cdn.shopify.com/s/files/1/0428/6975/1967/files/dirixini.pdf
    • https://cdn.shopify.com/s/files/1/0428/5900/4070/files/86123254442.pdf
    • https://cdn.shopify.com/s/files/1/0434/7301/0845/files/15201231063.pdf
    • https://cdn.shopify.com/s/files/1/0430/2805/4169/files/xegagimilipeguparo.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/30740110423.pdf
    • https://cdn.shopify.com/s/files/1/0436/6965/1606/files/cant_stop_wont_stop_movie.pdf
    • https://cdn.shopify.com/s/files/1/0436/8728/0790/files/36789972353.pdf
    • https://cdn.shopify.com/s/files/1/0427/7462/6470/files/tipowikagikijotofaruzu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 7

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000052cf.bin
e525599153b1ef119dc5358a4c056afc7452f499099d7c6e6881af35968bfbca
pdf-font-stream PDF embedded font (sfnt) at offset 0x52CF 8512 bytes
font_01_sfnt_off00006f65.bin
0aee01bf90ae8e0af14d1bf12f094e6c9dbc1885b0ea18dc49b42193cb5e78b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F65 5448 bytes
font_02_sfnt_off000081b5.bin
bbe62571d967bdb1411a5e35c3e1558c665c432f259f41461023933dda876a1c
pdf-font-stream PDF embedded font (sfnt) at offset 0x81B5 2060 bytes
font_03_sfnt_off00008b52.bin
bafa3f775539b8d860df3e40128e52b02033a0e242cc54ebb305f061906f79ad
pdf-font-stream PDF embedded font (sfnt) at offset 0x8B52 6820 bytes
font_04_sfnt_off00009d9f.bin
da7e16ee4bfa7b4211b9026fc463626c6171ba7013e20bf8882fff16728fb621
pdf-font-stream PDF embedded font (sfnt) at offset 0x9D9F 10360 bytes
font_05_sfnt_off0000c112.bin
15a68420f1c377824b8c1fd571ac7c30556db1b4bc05006bf44ec3f6c6c83208
pdf-font-stream PDF embedded font (sfnt) at offset 0xC112 16120 bytes
font_06_sfnt_off0000d5f9.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0xD5F9 4324 bytes