Malicious PDF — malware analysis report

Static analysis result for SHA-256 c53041a5c6f3315b…

MALICIOUS

PDF

48.7 KB Created: 2020-08-22 22:48:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0da00c2c2c0bb66b6bb59f199f7e693e SHA-1: 09229a8135de5a7fc063a980291c61c1b7dc4c5d SHA-256: c53041a5c6f3315b6169fdc444339be7fa2a3c4020862a3893fc10195024988b
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a high number of external links, many of which point to a link farm hosted on Shopify, and one critical link to a known malicious redirector. The document body, though heavily obfuscated, contains the URL for the malicious redirector, suggesting the primary intent is to lure the user to this malicious site. The presence of a 'download button' heuristic further supports this lure-based attack pattern.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=awdhesh+premi+bhojpuri+song++free
    • http://files.building313.com/uploads/1/3/1/3/131383892/zeniwarijotepis_pejetaderamu_zegirujili_garalafenar.pdf
    • http://files.teressaking.com/uploads/1/3/2/6/132681863/bemivisivanuz_volinawa_foson.pdf
    • http://vovuje.ackgs.com/uploads/1/3/1/8/131856772/a187a878d313.pdf
    • https://cdn.shopify.com/s/files/1/0433/0536/9758/files/computer_awareness_book_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0428/0818/0895/files/ffxi_smithing_guide.pdf
    • https://cdn.shopify.com/s/files/1/0428/3973/6487/files/phpmailer_smtp_imap.pdf
    • https://cdn.shopify.com/s/files/1/0433/4754/2175/files/descriptive_research_paper_sample.pdf
    • https://cdn.shopify.com/s/files/1/0429/3056/9382/files/pengertian_politik_identitas.pdf
    • https://cdn.shopify.com/s/files/1/0434/6934/0822/files/22206451057.pdf
    • https://cdn.shopify.com/s/files/1/0431/7744/3483/files/zixidofumu.pdf
    • https://cdn.shopify.com/s/files/1/0430/6416/4506/files/gre_official_guide.pdf
    • https://cdn.shopify.com/s/files/1/0431/7931/1268/files/junefowimufameken.pdf
    • https://cdn.shopify.com/s/files/1/0433/0697/5382/files/godiwuxutazodisizago.pdf
    • https://cdn.shopify.com/s/files/1/0461/8236/7386/files/82274378374.pdf
    • https://cdn.shopify.com/s/files/1/0433/9970/8821/files/5670770780.pdf
    • https://cdn.shopify.com/s/files/1/0434/1334/0312/files/22362867815.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000060fb.bin
1326fbc4033378afb1c86c674fe71bfdb2faa1b3332edeb49f8a58fd0a9c7cd5
pdf-font-stream PDF embedded font (sfnt) at offset 0x60FB 5508 bytes
font_01_sfnt_off000073a7.bin
eee17ddde8e1e4ee490b620d71de92ae871d24f1dd4b075e2d1fbcb90f78ee7c
pdf-font-stream PDF embedded font (sfnt) at offset 0x73A7 14244 bytes
font_02_sfnt_off0000a041.bin
f81f9bb65eb019d7593257dec04188fe3b3421c70974ba34dfc92eaccb21b54b
pdf-font-stream PDF embedded font (sfnt) at offset 0xA041 5228 bytes