Malicious PDF — malware analysis report

Static analysis result for SHA-256 bdda615ccf6a6594…

MALICIOUS

PDF

97.4 KB Created: 2020-08-12 11:11:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4d4e53faddede31426919d03b84f2fc2 SHA-1: 8c2bcaa5a919db4b5384a1cc8b8e2cfe022d322f SHA-256: bdda615ccf6a6594b1055a0aa233b2e0c7c29e6fa76eb58eb654077c002e2387
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains multiple embedded links, with a critical heuristic firing indicating a malicious redirector link to 'ttraff.com'. Another critical heuristic identified a PDF link farm, suggesting an attempt to manipulate search engine results or distribute malicious content. The document body, though heavily obfuscated, contains the same redirect URL, reinforcing the malicious intent. The primary attack pattern involves luring the user to a malicious site via embedded links.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=diphthongs+examples+words+pdf
    • http://files.alligatoralliance.com/uploads/1/3/0/7/130775536/f20f36ae.pdf
    • http://files.papermagicbook.com/uploads/1/3/1/8/131860787/nelakojopotazedi.pdf
    • http://files.suemurrayphotographer.com/uploads/1/3/1/4/131437493/588f8.pdf
    • http://fumigete.adamsbiz.com/uploads/1/3/1/4/131453494/8ba2d03.pdf
    • http://files.beauteholisticskincare.com/uploads/1/3/1/4/131412235/xulemegaguzaneliwa.pdf
    • https://cdn.shopify.com/s/files/1/0446/7628/4569/files/water_pollution_consequences.pdf
    • https://cdn.shopify.com/s/files/1/0429/3269/9302/files/tipos_de_bacterias_gram_negativas.pdf
    • https://cdn.shopify.com/s/files/1/0446/9240/6428/files/excel_macros_complete_tutorial.pdf
    • https://cdn.shopify.com/s/files/1/0432/7417/4632/files/nipidagubaviwigikadiki.pdf
    • https://cdn.shopify.com/s/files/1/0435/6859/5112/files/contact_form_7_us_states_dropdown.pdf
    • https://cdn.shopify.com/s/files/1/0436/5330/0377/files/59680288484.pdf
    • https://cdn.shopify.com/s/files/1/0439/4074/1275/files/15906260999.pdf
    • https://cdn.shopify.com/s/files/1/0431/6083/0116/files/ruborojubo.pdf
    • https://cdn.shopify.com/s/files/1/0433/3967/7861/files/orbit_6_station_timer_manual_57161.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/21659337375.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/dipipopiluniwewikojidil.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d8bf.bin
d87485d8355dbdb0064ac64c534936fb975cb90308176d2a3261a105f236586d
pdf-font-stream PDF embedded font (sfnt) at offset 0xD8BF 7900 bytes
font_01_sfnt_off0000f313.bin
aad3fcc0336c7e5c9553a918edea3d392b7a9f2feb0b586ab4344c513485a147
pdf-font-stream PDF embedded font (sfnt) at offset 0xF313 5616 bytes
font_02_sfnt_off00010608.bin
64e81ef5f77ee06f7b6d9999e662fa05a4706d5e50e1149be8643144bca69a29
pdf-font-stream PDF embedded font (sfnt) at offset 0x10608 6480 bytes
font_03_sfnt_off00011751.bin
dcc0a70d952d685641d000524128aaf266850ae03d193be9504de7aeaff81a45
pdf-font-stream PDF embedded font (sfnt) at offset 0x11751 26148 bytes
font_04_sfnt_off000161c3.bin
6f37f859521bb7085494b614750b29a097ece4d74f652abeb4704c9c3c139623
pdf-font-stream PDF embedded font (sfnt) at offset 0x161C3 16188 bytes