Malicious PDF — malware analysis report

Static analysis result for SHA-256 d6b936402ef7b7e3…

MALICIOUS

PDF

43.3 KB Created: 2020-08-27 17:30:58 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6916a503a6c2ad574cb3115c73ff2814 SHA-1: df7c5f79b73575517cbb612ef5c619df64ff6937 SHA-256: d6b936402ef7b7e34e634857d06c9fbf92ffe1a9dde0fbd20b6dd7cadc751b63
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.001 User Execution: Malicious Link T1059.001 PowerShell

The PDF file contains numerous embedded links, with a critical heuristic firing for a malicious redirector. The primary malicious URL identified is https://ttraff.club/pify?keyword=sistema+abierto+cerrado+y+aislado+ejemplos, which is likely used to redirect users to a harmful site. The document body also contains references to other URLs, including benign Shopify links and an additional unknown URL hosted on egpcrafts.com, suggesting a link farm or redirection strategy.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/pify?keyword=sistema+abierto+cerrado+y+aislado+ejemplos
    • http://zalefomun.egpcrafts.com/uploads/1/3/2/8/132816036/725677.pdf
    • https://cdn.shopify.com/s/files/1/0436/0303/4276/files/macbeth_act_4_study_guide.pdf
    • https://cdn.shopify.com/s/files/1/0431/0397/7634/files/lozodudofogofisofibowet.pdf
    • https://cdn.shopify.com/s/files/1/0440/6083/6005/files/some_important_full_forms_related_computer.pdf
    • https://cdn.shopify.com/s/files/1/0429/3555/0118/files/sales_executive_interview_questions_pdf.pdf
    • https://cdn.shopify.com/s/files/1/0431/7026/7291/files/xapunozazogirezi.pdf
    • https://cdn.shopify.com/s/files/1/0430/6527/8625/files/jilotipujasifiwuwapibexa.pdf
    • https://cdn.shopify.com/s/files/1/0431/3910/4929/files/32843988550.pdf
    • https://cdn.shopify.com/s/files/1/0463/1815/7989/files/nozerovimisofisud.pdf
    • https://cdn.shopify.com/s/files/1/0433/6877/5841/files/22671547504.pdf
    • https://cdn.shopify.com/s/files/1/0434/0459/1255/files/50031851357.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000066ae.bin
c4d23f076353a3695f7d1b9cd540c439239463a8e079aabaa5b321dcd968e205
pdf-font-stream PDF embedded font (sfnt) at offset 0x66AE 5640 bytes
font_01_sfnt_off000079ba.bin
0006b6eabc7758f298fade3f7543b40ec832a82f2b64b6dac4bf74d3e154f29a
pdf-font-stream PDF embedded font (sfnt) at offset 0x79BA 11264 bytes