Malicious PDF — malware analysis report

Static analysis result for SHA-256 bae76c814e636aae…

MALICIOUS

PDF

41.1 KB Created: 2020-09-02 02:37:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 954b64b844e3a8d656f31f4f1a353a5c SHA-1: f75c7c005eb0992702128b4e41cf63efbb4ca2f5 SHA-256: bae76c814e636aaeb902101dbbf24ced242b7f57aa76938f0af42795959e38f2
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.me/wix?keyword=bsf+bharti+online+form+date+2018'. The document body also contains this URL, suggesting it is the primary lure. The file also contains a large number of external PDF links, many hosted on Shopify, which is indicative of a link farm used for SEO poisoning or to obscure the malicious redirector. The overall pattern suggests a phishing or scam attempt.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=bsf+bharti+online+form+date+2018
    • https://cdn.shopify.com/s/files/1/0431/2639/0933/files/95902513895.pdf
    • https://cdn.shopify.com/s/files/1/0431/9176/3105/files/computer_science_and_information_technology_syllabus.pdf
    • https://cdn.shopify.com/s/files/1/0428/5713/6294/files/94454915274.pdf
    • https://cdn.shopify.com/s/files/1/0428/8898/6787/files/18708625703.pdf
    • https://cdn.shopify.com/s/files/1/0429/8116/3157/files/75186424730.pdf
    • https://cdn.shopify.com/s/files/1/0439/0954/6136/files/65906876185.pdf
    • https://cdn.shopify.com/s/files/1/0433/5340/7646/files/pufajuronesesew.pdf
    • https://cdn.shopify.com/s/files/1/0447/2134/0570/files/maths_worksheets_for_preschoolers.pdf
    • https://cdn.shopify.com/s/files/1/0427/6797/4556/files/mujexilanubodakod.pdf
    • https://cdn.shopify.com/s/files/1/0431/3081/4626/files/convert_in_word_document_for_edit.pdf
    • https://static.usrfiles.com/ugd/3de8a6_c78119b6614a4e09a851692f433646ee.pdf
    • https://static.usrfiles.com/ugd/64e449_9616cc206fcf47c8bb4bc1f3a26bf287.pdf
    • https://static.usrfiles.com/ugd/93971e_fd20c752b30c4f699f93268c2e04dcc7.pdf
    • https://static.usrfiles.com/ugd/5b604d_0d6950e464c14006970a5a012bfa81b4.pdf
    • https://static.usrfiles.com/ugd/8b9728_c115f5ec556d42b195f9c12f33d4d653.pdf
    • https://static.usrfiles.com/ugd/b8c837_5efe5833b3c54858ac7df3b96a4a7ffc.pdf
    • https://static.usrfiles.com/ugd/b8c837_50fe117e663543b1a93ec9e9748e6e84.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000609b.bin
93c0805f2f2e797a2b04bde8187e97a9fcc8387097aee92dbf4de30a9cee8114
pdf-font-stream PDF embedded font (sfnt) at offset 0x609B 5856 bytes
font_01_sfnt_off0000745a.bin
d7ec2e353c9f781887123c62370311123d2834a78e52ee2e37f9214f98118251
pdf-font-stream PDF embedded font (sfnt) at offset 0x745A 10364 bytes