Malicious PDF — malware analysis report

Static analysis result for SHA-256 cc31d1e20a8b49f8…

MALICIOUS

PDF

236.6 KB Created: 2020-08-10 01:12:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1ac402b4214c8e144f860348ead9e3d1 SHA-1: f86ee84e6d12fa263810cacb7967bcc6db03ea57 SHA-256: cc31d1e20a8b49f8ade92b8283bebb2c2421b94acdf190a12d4ed65fad9a9e4d
100 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://ttraff.ru/pify?keyword=japanese+colonization+in+the+philippines+pdf'. This URL is combined with a high severity heuristic indicating an advance-fee scam lure, suggesting the document's purpose is to trick the user into visiting the malicious link under false pretenses. The document body, though heavily obfuscated, contains the same URL, reinforcing its malicious intent.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=japanese+colonization+in+the+philippines+pdf
    • http://files.larsonartgallery.com/uploads/1/3/1/4/131411896/2643385.pdf
    • http://files.cloverbands.com/uploads/1/3/1/4/131455232/7912624.pdf
    • http://laruva.trigonarchitect.com/uploads/1/3/1/8/131856158/bopub-tefid-pitiza-gosej.pdf
    • https://cdn.shopify.com/s/files/1/0434/6131/2676/files/jinuj.pdf
    • https://cdn.shopify.com/s/files/1/0438/6488/3355/files/les_adjectif_numraux_cardinaux.pdf
    • https://cdn.shopify.com/s/files/1/0430/3981/7890/files/42448027875.pdf
    • https://cdn.shopify.com/s/files/1/0448/6466/7810/files/john_deere_790_tractor.pdf
    • https://cdn.shopify.com/s/files/1/0431/4526/5312/files/mijonubogavaremun.pdf
    • https://cdn.shopify.com/s/files/1/0428/9993/1295/files/femedirefowanunajiz.pdf
    • https://cdn.shopify.com/s/files/1/0431/0892/5600/files/rimupo.pdf
    • https://cdn.shopify.com/s/files/1/0431/6469/6732/files/moviestarplanet_hack_no_survey_no_download_2015.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/9009713252.pdf
    • https://cdn.shopify.com/s/files/1/0435/7410/0127/files/imessage_for_android_apk.pdf
    • https://cdn.shopify.com/s/files/1/0435/7862/2111/files/benisupi.pdf
    • https://cdn.shopify.com/s/files/1/0430/9660/4825/files/destin_surf_report.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00034153.bin
8d4a6a372787b71a47a6c652b092aeb05c27a9bef38c3b1a1485215201ba8f63
pdf-font-stream PDF embedded font (sfnt) at offset 0x34153 4564 bytes
font_01_sfnt_off0003514f.bin
980445b6e4419bbdaefb30d2b974524424e8e3f49a5880f2ab9367b37a696733
pdf-font-stream PDF embedded font (sfnt) at offset 0x3514F 5184 bytes
font_02_sfnt_off000362fe.bin
8a8ae28aabee66468573ce3bb66e04bdf1723529bcebd0c30a4fc18c553d0ec9
pdf-font-stream PDF embedded font (sfnt) at offset 0x362FE 12436 bytes
font_03_sfnt_off00038b74.bin
d94d22dc66d422a08ef26574f1e9d0f41d030441ab145d1cf4963c94125f2da5
pdf-font-stream PDF embedded font (sfnt) at offset 0x38B74 16772 bytes