Malicious PDF — malware analysis report

Static analysis result for SHA-256 c4a8ddcd1b973a7f…

MALICIOUS

PDF

48.5 KB Created: 2020-09-04 06:36:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7473d03e390e3ea0854f56f4381872cd SHA-1: b845e6a51dcfddd6b315350f96eec84ec182e149 SHA-256: c4a8ddcd1b973a7fbe251a96b36ab92a7c7eac35e83ba172cef880535447bc46
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.link/wix?keyword=albania+report+european+commission'. Additionally, it exhibits a PDF link farm heuristic, with numerous external PDF links, one of which is 'https://cdn.shopify.com/s/files/1/0429/7247/9647/files/vimijidiwabomizowuvavipab.pdf'. The document body, though heavily obfuscated, contains text fragments related to 'Albania report european commission', reinforcing the lure. The primary attack pattern involves redirecting the user to malicious infrastructure via the embedded link.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=albania+report+european+commission
    • https://cdn.shopify.com/s/files/1/0429/7247/9647/files/vimijidiwabomizowuvavipab.pdf
    • https://cdn.shopify.com/s/files/1/0429/4737/9356/files/caller_id_changer_app_free.pdf
    • https://cdn.shopify.com/s/files/1/0448/0784/8096/files/bindiya_bole_kya_bole_gana.pdf
    • https://cdn.shopify.com/s/files/1/0428/6968/6431/files/dixiv.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/nomevorijodasulalo.pdf
    • https://cdn.shopify.com/s/files/1/0468/9559/5682/files/dobomegerogowelujewe.pdf
    • https://static.usrfiles.com/ugd/b50c55_18375a9e726b4c16be1c1033af36c1c9.pdf
    • https://static.usrfiles.com/ugd/b5472a_4103a1dacb944f5ba63afbadf4691b02.pdf
    • https://cdn.shopify.com/s/files/1/0434/5308/7911/files/c_major_chord_piano.pdf
    • https://cdn.shopify.com/s/files/1/0438/6874/9979/files/wivipopibepomotik.pdf
    • https://cdn.shopify.com/s/files/1/0433/3951/4006/files/debit_and_credit_accounting_cheat_sheet.pdf
    • https://cdn.shopify.com/s/files/1/0432/5795/4467/files/56827591117.pdf
    • https://cdn.shopify.com/s/files/1/0432/7804/1244/files/21005705516.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007426.bin
c45c9c16fc39dbb448f0b61d5f87de7127fb40b91ca0a35e650dbe116c977910
pdf-font-stream PDF embedded font (sfnt) at offset 0x7426 5088 bytes
font_01_sfnt_off00008547.bin
35023896600f35eebe146db70c625c3167a8c42f55b13b46816bd395fdf07553
pdf-font-stream PDF embedded font (sfnt) at offset 0x8547 9796 bytes
font_02_sfnt_off0000a6c9.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0xA6C9 4324 bytes