Malicious PDF — malware analysis report

Static analysis result for SHA-256 cacd88ade8a40567…

MALICIOUS

PDF

53.6 KB Created: 2020-07-29 04:00:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 559e412a2a8bdc3162ed5570b6527bac SHA-1: 61d3c8cc5b3455d9f0f9b83472ec2e9d2bb3f991 SHA-256: cacd88ade8a405672305a31f7812e9ec84054208ab614fad0644e0365e6dde8b
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=genki+answer+key+second+edition+pdf'. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded URLs, many of which are hosted on Shopify. The document body, though heavily obfuscated, contains metadata suggesting it was generated by wkhtmltopdf. The primary malicious IOC is the redirector URL, which likely serves as a gateway to further malicious content or phishing pages.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=genki+answer+key+second+edition+pdf
    • http://files.darrennixon.com/uploads/1/3/0/7/130738719/kabisegunelokimujix.pdf
    • http://files.disabilitymanagmentsolutions.ca/uploads/1/3/1/4/131437149/7b70cc.pdf
    • http://files.ambergirl.org/uploads/1/3/1/1/131164475/1862fbfb4d78b28.pdf
    • http://files.studiosisu.net/uploads/1/3/1/3/131398597/nawezuf.pdf
    • http://files.jacoberdman.ca/uploads/1/3/0/9/130969146/pogifakipi-nemavavogo-nijudiwodexole-bisofenizopamox.pdf
    • http://files.ambergirl.org/uploads/1/3/1/1/1
    • https://cdn.shopify.com/s/files/1/0428/6778/5884/files/sasabazunipolel.pdf
    • https://cdn.shopify.com/s/files/1/0431/5942/1092/files/xonopiw.pdf
    • https://cdn.shopify.com/s/files/1/0434/2788/9302/files/68966854508.pdf
    • https://cdn.shopify.com/s/files/1/0438/0344/3361/files/zotaxijerulogivom.pdf
    • https://cdn.shopify.com/s/files/1/0431/8104/7965/files/47922341045.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/sibubemazalomasedexikeme.pdf
    • https://cdn.shopify.com/s/files/1/0428/6509/8908/files/44782457504.pdf
    • https://cdn.shopify.com/s/files/1/0431/5735/6710/files/20430928090.pdf
    • https://cdn.shopify.com/s/files/1/0428/0070/9791/files/85172347570.pdf
    • https://cdn.shopify.com/s/files/1/0435/4893/4295/files/72422742271.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000070b3.bin
f64509340f08da7e4aecfe03cc962331926dcc1e44daf53d44d64a610811c2d0
pdf-font-stream PDF embedded font (sfnt) at offset 0x70B3 6696 bytes
font_01_sfnt_off00008799.bin
eed85e069dcea17a793f7347fa312d2bda26709872d233acd610e9f5a12a4d8a
pdf-font-stream PDF embedded font (sfnt) at offset 0x8799 5196 bytes
font_02_sfnt_off0000996b.bin
0970755a909ab8693fbf19cb5831dee24f38341772241918ca2547857c4eb108
pdf-font-stream PDF embedded font (sfnt) at offset 0x996B 14996 bytes