Malicious PDF — malware analysis report

Static analysis result for SHA-256 d3d1a32f4ae79fb1…

MALICIOUS

PDF

42.9 KB Created: 2020-08-01 07:26:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7f838361a172a2a345798f5d733bf35d SHA-1: a3440a0d0353647ab0fc99ff6cdf1526f5c6abed SHA-256: d3d1a32f4ae79fb1eb696f51c51faf5281cdc4d5054b0416bc8443be2b494d3f
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.cc/pify?keyword=mariner+25+hp+outboard+manual+pdf'. This indicates the document's primary purpose is to redirect users to malicious sites. The presence of a PDF link farm further supports the malicious intent by attempting to distribute numerous links, likely for SEO poisoning or to obscure the malicious destination. No scripts were extracted, and the document body was heavily obfuscated, but the link analysis is sufficient to determine the attack pattern.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=mariner+25+hp+outboard+manual+pdf
    • http://files.madisonstinemetz.com/uploads/1/3/0/7/130739570/7447172.pdf
    • http://files.defenceco.com/uploads/1/3/1/3/131383478/c30fbe7a389.pdf
    • http://files.weekendinquest.org/uploads/1/3/1/4/131437005/siduzamelofubaf_tiruwedurutu_tadodimomivo_siparexenovewis.pdf
    • http://files.mrsmarxsfirstgrade.com/uploads/1/3/1/4/131437680/024d49d3a7a870.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/14192803693.pdf
    • https://cdn.shopify.com/s/files/1/0435/3101/0199/files/92502664996.pdf
    • https://cdn.shopify.com/s/files/1/0440/7522/1142/files/wixijowisakavivevap.pdf
    • https://cdn.shopify.com/s/files/1/0439/1688/6184/files/jotibezutagerugujaj.pdf
    • https://cdn.shopify.com/s/files/1/0431/7193/8453/files/40538624749.pdf
    • https://cdn.shopify.com/s/files/1/0428/8148/2919/files/15174979926.pdf
    • https://cdn.shopify.com/s/files/1/0435/4444/5092/files/degaxipivikopinawaj.pdf
    • https://cdn.shopify.com/s/files/1/0430/3018/4098/files/62130549574.pdf
    • https://cdn.shopify.com/s/files/1/0430/1937/0659/files/xurunijijet.pdf
    • https://cdn.shopify.com/s/files/1/0436/6453/9798/files/mitefawizu.pdf
    • https://cdn.shopify.com/s/files/1/0429/1916/6105/files/53777320492.pdf
    • https://cdn.shopify.com/s/files/1/0431/9775/9643/files/89884255213.pdf
    • https://cdn.shopify.com/s/files/1/0427/6230/5702/files/57781544921.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006005.bin
75ed9b04c55d31aa2b7569cf2961c6a2fc7b2a07d5ee287b1425c119cd022b70
pdf-font-stream PDF embedded font (sfnt) at offset 0x6005 5504 bytes
font_01_sfnt_off000072a3.bin
b8e61afd57118d05814281e9451cf2481a6a0f0bf522d655db55babe2ed45a16
pdf-font-stream PDF embedded font (sfnt) at offset 0x72A3 14288 bytes