Malicious PDF — malware analysis report

Static analysis result for SHA-256 c8deac180cae0e04…

MALICIOUS

PDF

58.9 KB Created: 2020-08-12 22:52:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5541a84a4f566d91e68d7ee14f0d2a37 SHA-1: d0b1b85d97ff79fd54aba1c0ec2182b7d6cb5111 SHA-256: c8deac180cae0e04b6b61ff64b25db2b289f16408eed56437afc2a5196fafaa9
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link to a known malicious redirector, ttraff.cc, which is likely used to obscure the final destination of the malicious payload. The document body also contains numerous links to other PDFs hosted on various domains, suggesting a link farm or redirection strategy. No scripts were extracted, but the presence of a malicious redirector link is a strong indicator of a phishing or malware distribution attempt.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=sylvia+day+afterburn+pdf
    • http://files.nc-so.org/uploads/1/3/1/0/131071249/5398313.pdf
    • http://files.bluebucketcabin.com/uploads/1/3/1/4/131437308/fibokosajifuv.pdf
    • http://gigojopi.bellamymansion.org/uploads/1/3/0/8/130874674/1446698.pdf
    • http://files.starlapps.com/uploads/1/3/2/7/132712415/vezopusufubodibelux.pdf
    • http://files.bristoldentalsociety.co.uk/uploads/1/3/0/7/130739783/mofufa.pdf
    • https://cdn.shopify.com/s/files/1/0440/1417/4358/files/coleman_rv_air_conditioners_manual.pdf
    • https://cdn.shopify.com/s/files/1/0429/8987/9445/files/49808152266.pdf
    • https://cdn.shopify.com/s/files/1/0428/8043/4342/files/11403874844.pdf
    • https://cdn.shopify.com/s/files/1/0434/7127/4146/files/12663303527.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/dijev.pdf
    • https://cdn.shopify.com/s/files/1/0433/1828/0357/files/zekigedejewojo.pdf
    • https://cdn.shopify.com/s/files/1/0431/8239/1451/files/13562232009.pdf
    • https://cdn.shopify.com/s/files/1/0428/3593/5388/files/16456591565.pdf
    • https://cdn.shopify.com/s/files/1/0430/7497/7945/files/bakemefoviwud.pdf
    • https://cdn.shopify.com/s/files/1/0429/8421/0583/files/31591968761.pdf
    • https://cdn.shopify.com/s/files/1/0432/3488/5792/files/copious_dogs_mod_1._7_10.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000061cb.bin
1c4d7d289e303cda7cad05b7bd97fe51aae28cb5494c6d4806422661c04cf874
pdf-font-stream PDF embedded font (sfnt) at offset 0x61CB 5260 bytes
font_01_sfnt_off000073bd.bin
b91f3c26f37c28538ed09035cbea6f9221827f1e30b50c452f08cc820bcc167b
pdf-font-stream PDF embedded font (sfnt) at offset 0x73BD 3720 bytes
font_02_sfnt_off00007f20.bin
cddd00b727e26506d279c4b8130839908b3cb6fb6270cffe0bc9aa95f80cba20
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F20 13668 bytes
font_03_sfnt_off0000ab25.bin
6bdf0468782905378d7f9f876db6c07b19d5bdf3f84934a4f4983aedf31f7953
pdf-font-stream PDF embedded font (sfnt) at offset 0xAB25 16236 bytes
font_04_sfnt_off0000c0bf.bin
b8f64c45775f049b019234adb231a53bbe07105ca07591ef9ab71171b9eed9f0
pdf-font-stream PDF embedded font (sfnt) at offset 0xC0BF 8644 bytes