Malicious PDF — malware analysis report

Static analysis result for SHA-256 cd2f1f82944bc734…

MALICIOUS

PDF

115.9 KB Created: 2020-07-28 19:25:22 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 319fd1fede71f053174b01dbb48d177b SHA-1: 9389cb460a58c1c270a15b46e7559424ebb79409 SHA-256: cd2f1f82944bc734c3832eb4981ac6428cf72f96a79ff3fdd44fb4b53989d183
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. This URL is associated with a lure for 'Bahubali 2 full movie telugu lo', indicating a phishing or content-luring attack. The PDF also hosts a large number of external links, many pointing to Shopify domains, suggesting a link farm or distribution mechanism. No scripts were extracted, but the primary attack vector appears to be the malicious redirector.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=bahubali+2+full+movie+telugu+lo
    • http://files.5starbuild.com/uploads/1/3/0/9/130969065/9748516.pdf
    • http://files.chefleslieann.com/uploads/1/3/1/8/131871424/mokezobazuluparuri.pdf
    • http://files.dreamcometruevacation.com/uploads/1/3/1/6/131606890/85d68e6b9bed08e.pdf
    • http://files.jamesaaronhogan.com/uploads/1/3/1/6/131606262/wodimuvifos_zezuwamogipe_bezexew_xejawuwir.pdf
    • http://files.cariblit.org/uploads/1/3/1/4/131406717/podexolifonubap_menisalokafu_birigegixuxud_rakuj.pdf
    • https://cdn.shopify.com/s/files/1/0433/7529/6677/files/bexefenijiji.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/ruketisoren.pdf
    • https://cdn.shopify.com/s/files/1/0429/8774/9525/files/jegod.pdf
    • https://cdn.shopify.com/s/files/1/0432/0457/5387/files/linutezivewisonuga.pdf
    • https://cdn.shopify.com/s/files/1/0434/4017/7314/files/fidoxil.pdf
    • https://cdn.shopify.com/s/files/1/0431/2757/0596/files/71172486657.pdf
    • https://cdn.shopify.com/s/files/1/0433/1690/4104/files/37937035572.pdf
    • https://cdn.shopify.com/s/files/1/0430/3123/2674/files/84668984214.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/marifurozijuzaledenikegi.pdf
    • https://cdn.shopify.com/s/files/1/0429/5199/9637/files/gijibonuwadawugiwimobeza.pdf
    • https://cdn.shopify.com/s/files/1/0429/6186/2810/files/81457168238.pdf
    • https://cdn.shopify.com/s/files/1/0432/5857/7046/files/jupifuwikapoku.pdf
    • https://cdn.shopify.com/s/files/1/0430/9562/1796/files/29552449667.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00014ace.bin
e0cace0fbb8ed1ed38388b3f0c286755c8210c5fc51d41ebee94f99f66d87297
pdf-font-stream PDF embedded font (sfnt) at offset 0x14ACE 12404 bytes
font_01_sfnt_off0001738c.bin
1e994a3950978794558cd3a743b7a268273975fb40b0f14f249695f9bea3c1e7
pdf-font-stream PDF embedded font (sfnt) at offset 0x1738C 5064 bytes
font_02_sfnt_off000184e7.bin
f41d133c8153a0ad5cf78b1ffca212896068cc32396f3bd5a59b3ed29ccf3840
pdf-font-stream PDF embedded font (sfnt) at offset 0x184E7 11164 bytes
font_03_sfnt_off0001ab38.bin
e296a61d2d303e35be9e1a35631556663d2780498efa7e8f3867bf557f172fe6
pdf-font-stream PDF embedded font (sfnt) at offset 0x1AB38 16164 bytes