Malicious PDF — malware analysis report

Static analysis result for SHA-256 cc2158f2635b7f9b…

MALICIOUS

PDF

44.5 KB Created: 2020-09-17 09:20:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5cde6ec20506a1eacf538f155fe8fa0f SHA-1: 6177f2b40f0557137addd7a32656fa16ef9b8d7e SHA-256: cc2158f2635b7f9b0a85e48dbf07e4962c98421ebaaea222f1c8c0076aa6732e
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a link disguised as a worksheet answer key. This link, 'https://ttraff.me/wix?keyword=genetics+of+sickle+cell+anemia+worksheet+answer+key', redirects to known malicious infrastructure. The file also contains a large number of external links, many of which point to Shopify domains, suggesting a link farm or redirection strategy. No scripts were extracted, but the primary malicious behavior is the redirection via the embedded link.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=genetics+of+sickle+cell+anemia+worksheet+answer+key
    • https://25f94a51-4
    • https://cdn.shopify.com/s/files/1/0436/0057/6669/files/killswitch_engage_my_curse.pdf
    • https://cdn.shopify.com/s/files/1/0437/6359/7466/files/8361952452.pdf
    • https://cdn.shopify.com/s/files/1/0432/0490/3067/files/ligaxewufizimemuzinodelo.pdf
    • https://cdn.shopify.com/s/files/1/0437/3594/1274/files/73801425056.pdf
    • https://cdn.shopify.com/s/files/1/0430/1442/2677/files/konuxirelevumof.pdf
    • https://eb7a127b-55b9-4a69-b359-7a2a2c931c87.filesusr.com/ugd/4c1554_202dbc179dbc4afe9ea139dd70e8b92f.pdf?index=true
    • https://e29ded64-38f5-4eed-a212-40e172c18d8d.filesusr.com/ugd/b148e5_4e6d895f2924432d8834055be864143f.pdf?index=true
    • https://a3f0be66-a022-4bbb-b5aa-3d88afbb0dc6.filesusr.com/ugd/e3c460_6949479b699f4cf897e6b6f730d5d400.pdf?index=true
    • https://9902fce5-2cce-4070-9949-2c88098e1d92.filesusr.com/ugd/3f8d85_c5186b617b764fa6be9a25fc27d2f32d.pdf?index=true
    • https://e2d5dd5a-8865-4e14-988a-632b83da05ce.filesusr.com/ugd/1b6cec_0fcaf7cbc62440cdb8e4d37219467410.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0431/1692/0996/files/52123082737.pdf
    • https://cdn.shopify.com/s/files/1/0430/7940/1632/files/xokezaviboz.pdf
    • https://cdn.shopify.com/s/files/1/0431/0971/2021/files/jajipurinubexi.pdf
    • https://689a4e8e-8ccb-4a4d-884e-34a1088e744c.filesusr.com/ugd/7dfe85_d01abba076c64e3a9623782f2a28bd73.pdf?index=true
    • https://25f94a51-48cc-4efd-8be6-cbd28a305d14.filesusr.com/ugd/1715bf_1503d25f47374657a00e33e5933424b9.pdf?index=true
    • https://0ade4590-ec6c-46f1-b3b0-05c7f9513d2b.filesusr.com/ugd/ff2e72_07f916331e9c47f1a5524c5061ab21b4.pdf?index=true
    • https://c77a2d65-1f00-44cb-9e74-64209244e2d0.filesusr.com/ugd/76156b_515b86e9f8cc47a59c73b4a10050bad3.pdf?index=true
    • https://21817981-e8d1-44f9-a0b6-e1edc6644474.filesusr.com/ugd/b8c837_ec1de70028b540e689ddf3a63c5c79ae.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000067f3.bin
55c7db66ea605c3f9ebf538b62c3d32af23ff25e707be93eebee4c6e9e8b11c3
pdf-font-stream PDF embedded font (sfnt) at offset 0x67F3 5408 bytes
font_01_sfnt_off00007a4c.bin
3a6c7bb7ef14dfa7864a9f476befee0502305bfb541e93a18cb1f2ca19093d92
pdf-font-stream PDF embedded font (sfnt) at offset 0x7A4C 13232 bytes