Malicious PDF — malware analysis report

Static analysis result for SHA-256 d7298bd8c2526a8f…

MALICIOUS

PDF

33.4 KB Created: 2020-08-30 17:04:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 90e404dbb9cc89f672198f51ad57ef25 SHA-1: 34c06e81a172cd0c53706c3e10c9553f3b665e1e SHA-256: d7298bd8c2526a8f7a37d2e7de7684526c4e781c7497b5a2b81f4fa9dc209896
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.cc/wix?keyword=kitab+betaljemur+pdf'. This indicates an attempt to direct users to a malicious site. The file also contains a large number of external PDF links, many hosted on Shopify, suggesting a link farm or SEO manipulation tactic to distribute malicious content. No scripts were extracted, and the document body is heavily obfuscated, but the presence of the malicious redirector URL is the primary indicator of malicious intent.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=kitab+betaljemur+pdf
    • https://cdn.shopify.com/s/files/1/0435/4929/4756/files/83491627607.pdf
    • https://cdn.shopify.com/s/files/1/0431/3032/3101/files/pert_math_study_guide.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/xoperesotojazi.pdf
    • https://cdn.shopify.com/s/files/1/0434/1334/0312/files/sijanoselivina.pdf
    • https://cdn.shopify.com/s/files/1/0438/1330/6530/files/backcountry_magazine_gear_guide_2020.pdf
    • https://cdn.shopify.com/s/files/1/0427/8360/4903/files/57547905710.pdf
    • https://cdn.shopify.com/s/files/1/0435/5915/7921/files/tijamawop.pdf
    • https://static.usrfiles.com/ugd/b8c837_515eaca7ad8d4dcc94d13af5426e78b9.pdf
    • https://static.usrfiles.com/ugd/3f0e57_6075536294744478be24f16e741884d6.pdf
    • https://static.usrfiles.com/ugd/7ef0dc_58cfc5dcd49c4323841fe2fbaddce877.pdf
    • https://static.usrfiles.com/ugd/ae059d_47ed92d5b09e4000867773a57c8173c9.pdf
    • https://static.usrfiles.com/ugd/b8c837_c5457d31b2ec4059a31b98aa8781f0d3.pdf
    • https://static.usrfiles.com/ugd/b8c837_6e43aeba9e79492dbf2cae5d68a824a9.pdf
    • https://static.usrfiles.com/ugd/eda9ba_c1a1b2147b2a44029173eaaa3d6aaadb.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000047dd.bin
373d134cb0bd091eae755b6ba1424657b0087874a20eaa9c961c98544918ea7e
pdf-font-stream PDF embedded font (sfnt) at offset 0x47DD 5192 bytes
font_01_sfnt_off00005970.bin
62d83118989fe875301195de0d02b49cf53c24ffcb69a4a80f8fd7ae339a9859
pdf-font-stream PDF embedded font (sfnt) at offset 0x5970 9344 bytes