Malicious PDF — malware analysis report

Static analysis result for SHA-256 d0fdbd93f577a54f…

MALICIOUS

PDF

55.4 KB Created: 2020-08-12 01:00:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4cb49194306714a41876519359bcd0c2 SHA-1: a1ecd336b9fec01627a6924ee39a2c37c7e8faff SHA-256: d0fdbd93f577a54f04271b1881076c06ed88ba8b4202e2e07f97753a6a7ea3f3
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a link farm and a direct link to a known malicious redirector, ttraff.cc. This indicates a social engineering attempt to lure users to malicious content, likely for further exploitation or malware delivery. The presence of numerous links to benign Shopify PDFs suggests an attempt to blend in with legitimate content while masking the malicious redirector.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wb?keyword=brahmastra%20advanced%20math%20book%20pdf
    • http://xitak.brokenknucklekustoms.com/uploads/1/3/2/7/132741555/sevaxoje-weponowi.pdf
    • http://files.amyluckenbill.com/uploads/1/3/1/3/131398117/rojakademavasu_vamidoxafavote_fozirovilepurot.pdf
    • http://files.nardamohammed.com/uploads/1/3/1/4/131408798/8673126.pdf
    • https://cdn.shopify.com/s/files/1/0437/0222/3013/files/jenafodazefepi.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/zugazad.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/dubisetebezurazoxodo.pdf
    • https://cdn.shopify.com/s/files/1/0432/7456/7833/files/natenamegone.pdf
    • https://cdn.shopify.com/s/files/1/0437/2702/8375/files/extrinsic_barriers_to_learning.pdf
    • https://cdn.shopify.com/s/files/1/0431/0951/5413/files/85536550368.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/punafaga.pdf
    • https://cdn.shopify.com/s/files/1/0433/7991/6967/files/motorola_dct2224_manual.pdf
    • https://cdn.shopify.com/s/files/1/0429/0812/3303/files/vonimazivawigureju.pdf
    • https://cdn.shopify.com/s/files/1/0429/0219/2284/files/apec_2020_agenda.pdf
    • https://cdn.shopify.com/s/files/1/0427/5326/1724/files/zipeduxetezijomu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000062e7.bin
241d38f0bdd14a7b385213b0625fffe0465bfc68fa9d4fee92c3ce25aa62b1c6
pdf-font-stream PDF embedded font (sfnt) at offset 0x62E7 5676 bytes
font_01_sfnt_off00007608.bin
4f60b374cbf2a68c08ee4e6e5bd880b9285dc74a309ed42da0b9c7a2c0026502
pdf-font-stream PDF embedded font (sfnt) at offset 0x7608 3720 bytes
font_02_sfnt_off00008160.bin
cf0d8fb5527eae19401dfc12654250517e7a38e3cc95ac791bee53c0147e1778
pdf-font-stream PDF embedded font (sfnt) at offset 0x8160 1972 bytes
font_03_sfnt_off00008ad3.bin
adef2a9b0bfeb3e7191b13557fac5b6feae15be6f1db03b4756a795512240d9d
pdf-font-stream PDF embedded font (sfnt) at offset 0x8AD3 12256 bytes
font_04_sfnt_off0000b1e3.bin
a27cdf3b38c2f88e791bbb439bf20f4fa1c5e0196732306a46b919300e861f60
pdf-font-stream PDF embedded font (sfnt) at offset 0xB1E3 9204 bytes