Malicious PDF — malware analysis report

Static analysis result for SHA-256 cdbd4f1fa77a31fa…

MALICIOUS

PDF

49.7 KB Created: 2020-09-10 05:11:40 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: aaf4d91d685364215c78af9778ea74f3 SHA-1: 681f707eac640bf5efa5e54ca0080977de2fb8dd SHA-256: cdbd4f1fa77a31faa2ac05d4394637f3db33eb4ca7792c753ad93d68021c1c2e
136 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a link to a known malicious redirector, disguised with a sense of urgency regarding a form correction. It also exhibits characteristics of a link farm, with numerous embedded links pointing to external PDFs, likely for SEO poisoning or to obscure the malicious redirector. The document body, though heavily obfuscated, contains the malicious redirector URL and several benign-looking Shopify URLs, one of which is also listed as an IOC due to its inclusion in the link farm.

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=gate+2020+form+correction+last+date
    • https://cdn.shopify.com/s/files/1/0427/4136/6951/files/fazulenabatopolipirub.pdf
    • https://cdn.shopify.com/s/files/1/0431/5529/2317/files/libris_mortis.pdf
    • https://cdn.shopify.com/s/files/1/0463/3837/5842/files/rulevuwikejarumubup.pdf
    • https://cdn.shopify.com/s/files/1/0435/4126/6591/files/ham_radio_bands.pdf
    • https://cdn.shopify.com/s/files/1/0432/4684/6107/files/levemakoberez.pdf
    • https://cdn.shopify.com/s/files/1/0427/4873/9740/files/reactive_attachment_disorder_in_adults.pdf
    • https://cdn.shopify.com/s/files/1/0437/0196/0854/files/47982919133.pdf
    • https://cdn.shopify.com/s/files/1/0441/1670/5432/files/partial_autocorrelation_function.pdf
    • https://cdn.shopify.com/s/files/1/0436/9950/3257/files/senubowirokujimufup.pdf
    • https://cdn.shopify.com/s/files/1/0431/9005/9176/files/14594359787.pdf
    • https://cdn.shopify.com/s/files/1/0431/4749/3536/files/cbse_syllabus_for_class_11_maths.pdf
    • https://cdn.shopify.com/s/files/1/0430/7507/6258/files/sql_server_report_builder_format_currency.pdf
    • https://cdn.shopify.com/s/files/1/0436/7450/1285/files/44213036958.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/50971407729.pdf
    • https://cdn.shopify.com/s/files/1/0431/9143/5422/files/16805409717.pdf
    • https://cdn.shopify.com/s/files/1/0452/9124/1634/files/pipewafuvugob.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000082f2.bin
a60b1d22841058f6bb3e818853c88181bf3073b79faaf1f5d3543d7d16f6f348
pdf-font-stream PDF embedded font (sfnt) at offset 0x82F2 5472 bytes
font_01_sfnt_off0000957b.bin
44d97a6f7101bd1ce1cb065de97890ed6d39b407de641a7ea5f3efc2e11ad9ee
pdf-font-stream PDF embedded font (sfnt) at offset 0x957B 10548 bytes