Malicious PDF — malware analysis report

Static analysis result for SHA-256 d9101354dd5d5390…

MALICIOUS

PDF

57.0 KB Created: 2020-07-09 08:55:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3fdd5c58cfed6545ce6f1fd12ad0809f SHA-1: 948892fc8762fff5e48e078cdab48725af66e1fc SHA-256: d9101354dd5d539013f3534e223a30f2ba6f93aaf2dd8f7b6ac15e873f44cbc7
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains numerous links, a common tactic for SEO spam and phishing. One critical heuristic identified a link to a known malicious redirector infrastructure at 'https://ttraff.com/wb?keyword=save%20base64%20pdf%20to%20file%20c#'. The document body, though partially corrupted, also contains this URL, suggesting the primary intent is to redirect users to malicious content. The file's structure and the presence of many external links indicate a link farm or redirection attack.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wb?keyword=save%20base64%20pdf%20to%20file%20c#
    • http://files.daventrydogtrainingclub.com/uploads/1/3/0/8/130873973/6745225.pdf
    • http://files.sanmateolimos.com/uploads/1/3/1/3/131383553/612544a.pdf
    • http://files.lhschoolsupplies.com/uploads/1/3/2/6/132695836/donafidoxakawunuzap.pdf
    • http://files.systemamusement.com/uploads/1/3/2/6/132696117/jusid-wuzizofoki-xanumep-nitusawo.pdf
    • http://files.framemysore.org/uploads/1/3/1/3/131384789/7349004.pdf
    • http://files.marketmovesmatt.com/uploads/1/3/0/8/130874629/nuvigure-bufagejiv.pdf
    • http://files.ileanaespejel.com/uploads/1/3/1/3/131380001/1136987.pdf
    • https://cdn.shopify
    • https://keloramufen.files.wordpress.com/2020/06/sofuwewet.pdf
    • https://nogilofonula.files.wordpress.com/2020/06/degisitunobeko.pdf
    • https://womimoxik.files.wordpress.com/2020/06/litupiwafesarovazux.pdf
    • https://fuwewomenupi.files.wordpress.com/2020/07/fikomakaxezorixu.pdf
    • https://zavoduf.files.wordpress.com/2020/07/rokuraxepuri.pdf
    • https://sunewizev.files.wordpress.com/2020/06/xawatak.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/memew.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/zupapinited.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/voriwatovetizejewadodo.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/kepudanunakadop.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/ganisififado.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008f5e.bin
8236fca21985eca44d485852ac70981c5d9acdaa743bf41624b2d6a0f1b68d6a
pdf-font-stream PDF embedded font (sfnt) at offset 0x8F5E 5280 bytes
font_01_sfnt_off0000a15e.bin
d23f2c8d110fd0c2a6c69ad0bad8048789294e3596b9ef18eda5c7cfc7836e43
pdf-font-stream PDF embedded font (sfnt) at offset 0xA15E 17232 bytes