Malicious PDF — malware analysis report

Static analysis result for SHA-256 bdab80aecb8582e6…

MALICIOUS

PDF

51.9 KB Created: 2020-08-18 13:07:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 75b66a565954998cfd055ed92a283ea9 SHA-1: 9a1b7b4b70ed28b6a01ab1d01d60d083cb87eb25 SHA-256: bdab80aecb8582e63c4b19c45cbdd68677e51976abd2bdd259b2200350189e8c
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.001 Malicious Link T1059.001 PowerShell

The PDF file contains a large number of external links, a technique often used for SEO poisoning or to distribute malicious content. One of these links, 'https://ttraff.cc/pify?keyword=prometheus+alertmanager+webhook+format', is identified as a malicious redirector. This suggests the document's primary purpose is to lure users to malicious websites. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the exact lure.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=prometheus+alertmanager+webhook+format
    • http://files.goshawarmastop.com/uploads/1/3/1/4/131437949/9ee79bbfbec46.pdf
    • https://cdn.shopify.com/s/files/1/0429/2132/8807/files/86854532227.pdf
    • https://cdn.shopify.com/s/files/1/0443/6888/7964/files/95266545571.pdf
    • https://cdn.shopify.com/s/files/1/0434/2287/5800/files/xuxuwutu.pdf
    • https://cdn.shopify.com/s/files/1/0429/3722/1276/files/gofifom.pdf
    • https://cdn.shopify.com/s/files/1/0433/7205/2643/files/room_on_the_broom_worksheets.pdf
    • https://cdn.shopify.com/s/files/1/0431/4244/7261/files/duramagokekoxas.pdf
    • https://cdn.shopify.com/s/files/1/0431/6695/7722/files/10117132454.pdf
    • https://cdn.shopify.com/s/files/1/0428/3177/3852/files/51082092003.pdf
    • https://cdn.shopify.com/s/files/1/0428/6296/8991/files/dunawuvavidovisoravizizok.pdf
    • https://cdn.shopify.com/s/files/1/0434/5518/5063/files/statutory_durable_power_of_attorney_texas.pdf
    • https://cdn.shopify.com/s/files/1/0430/3224/8469/files/analytical_chemistry_1_book.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/21800621301.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007f20.bin
9adfde8da49e23f2755798f9324ce573b7f27962eb9c554047d5947ff8983c16
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F20 5476 bytes
font_01_sfnt_off000091a9.bin
bd05f130b4d8a8d3c009ea5a72f9e88bde3668bd05949d40c3f1a6c8b4ef4e6e
pdf-font-stream PDF embedded font (sfnt) at offset 0x91A9 15864 bytes