Malicious PDF — malware analysis report

Static analysis result for SHA-256 d98f0a656cab7d31…

MALICIOUS

PDF

52.4 KB Created: 2020-08-13 21:56:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e0dc9ffe4a78834317854117a94180c0 SHA-1: d1672d84b9358c753c867b2132b3cfd69ea4b6c9 SHA-256: d98f0a656cab7d31055dd86d53ecc39ed21f79a695bf6970bfb9704579f3b937
130 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=ts+eamcet+bipc+allotment+order+2019'. This indicates the document is designed to redirect users to malicious infrastructure. Additionally, a PDF link farm heuristic was triggered, with many links hosted on cdn.shopify.com, suggesting an attempt to obscure the final destination or spread the malicious content. The document body, though heavily obfuscated, contains the same malicious URL and benign-looking PDF links, reinforcing the lure.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=ts+eamcet+bipc+allotment+order+2019
    • http://lodimal.lionscb.org/uploads/1/3/0/7/130738837/bifixupoxatumaleg.pdf
    • http://files.backcountrywinery.com/uploads/1/3/1/3/131398184/vuzolakigiwabonufap.pdf
    • http://files.jenkatz-buonincontro.com/uploads/1/3/1/3/131379099/tevib-judexosedu-dejosekapuva.pdf
    • http://files.edhgs.com/uploads/1/3/1/4/131408529/lujaremokike_nezuki_derunelizaxeti_kelabij.pdf
    • https://cdn.shopify.com/s/files/1/0432/7663/2214/files/duxeladilaxisemubi.pdf
    • https://cdn.shopify.com/s/files/1/0432/5107/3174/files/how_to_download_aadhaar_card_without_otp.pdf
    • https://cdn.shopify.com/s/files/1/0429/9515/5105/files/98903181558.pdf
    • https://cdn.shopify.com/s/files/1/0432/5274/4347/files/72219556399.pdf
    • https://cdn.shopify.com/s/files/1/0429/7578/9215/files/pokemon_fire_red_walk_through_walls_cheat.pdf
    • https://cdn.shopify.com/s/files/1/0438/9873/2696/files/complete_english_punctuation_rules_download.pdf
    • https://cdn.shopify.com/s/files/1/0429/8850/3203/files/35701506772.pdf
    • https://cdn.shopify.com/s/files/1/0428/9685/1111/files/les_anticoagulants_oraux_directs.pdf
    • https://cdn.shopify.com/s/files/1/0434/2530/0647/files/disotozuxukukesakumido.pdf
    • https://cdn.shopify.com/s/files/1/0433/7215/0947/files/lororuvuleb.pdf
    • https://cdn.shopify.com/s/files/1/0431/5319/5165/files/69613572653.pdf
    • https://cdn.shopify.com/s/files/1/0436/2669/2761/files/sizobime.pdf
    • https://cdn.shopify.com/s/files/1/0431/8350/5570/files/wexuzenup.pdf
    • https://cdn.shopify.com/s/files/1/0437/9102/4280/files/rogusururufunekavek.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007d44.bin
15baa11db7e64219b200fd8c95b2cf41e913acadc8ce59a1334ec6b4fbff7f59
pdf-font-stream PDF embedded font (sfnt) at offset 0x7D44 5576 bytes
font_01_sfnt_off0000900a.bin
22fd521c1066433507fa02f5fb015af4c0e8d8f2bd307cd15a620a22d5894df4
pdf-font-stream PDF embedded font (sfnt) at offset 0x900A 11084 bytes
font_02_sfnt_off0000b5b1.bin
05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176
pdf-font-stream PDF embedded font (sfnt) at offset 0xB5B1 4324 bytes