Malicious PDF — malware analysis report

Static analysis result for SHA-256 de90120478529365…

MALICIOUS

PDF

47.6 KB Created: 2020-08-24 10:56:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cdbf64e414d0182d6bd9db974799ccb3 SHA-1: a4971f1827f1b64e5014431c7bd34758b7381879 SHA-256: de90120478529365ec88b1c2fe054b6c4e49c3083ee61ea0e7fa91f0d9986ae3
160 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file exhibits characteristics of a link farm, with numerous embedded URLs, many pointing to external PDF files hosted on platforms like Shopify. One URL, 'https://ttraff.ru/pify?keyword=just+learn+mitcham+ofsted+report', is flagged as a malicious redirector. The presence of a 'LOLBin Run Command' heuristic suggests potential execution of system tools, although no specific script was extracted to detail this further. The overall pattern indicates a likely attempt to manipulate search engine results or distribute malicious content through a large number of links.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visible LOLBin command execution instruction high SE_LOLBIN_RUN_COMMAND
    Document contains instructions or visible command text involving Windows script/execution tools such as PowerShell, mshta, cmd, rundll32, or regsvr32
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=just+learn+mitcham+ofsted+report
    • http://nuxuj.philiphuddlestonephotography.com/uploads/1/3/1/1/131164497/7872d2c52b84210.pdf
    • http://jodugi.splashyouth.org/uploads/1/3/1/0/131070581/sabunoziraxin.pdf
    • http://fodef.zemanmfg.com/uploads/1/3/1/0/131070382/583d13c1cf.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/kepudanunakadop.pdf
    • https://cdn.shopify.com/s/files/1/0434/4568/2332/files/citroen_c4_pallas_2008_manual_ficha_tecnica.pdf
    • https://cdn.shopify.com/s/files/1/0431/1282/4986/files/service_tag_cmd.pdf
    • https://cdn.shopify.com/s/files/1/0429/0838/5439/files/wimiz.pdf
    • https://cdn.shopify.com/s/files/1/0428/6559/0438/files/besarasevunezarofusozi.pdf
    • https://cdn.shopify.com/s/files/1/0439/1557/5464/files/wifigaw.pdf
    • https://cdn.shopify.com/s/files/1/0435/6407/3128/files/pemex_business_plan_2020.pdf
    • https://cdn.shopify.com/s/files/1/0429/3538/6275/files/derikezogiz.pdf
    • https://cdn.shopify.com/s/files/1/0432/5454/6590/files/43050382494.pdf
    • https://cdn.shopify.com/s/files/1/0434/6114/8836/files/replace_function_in_r.pdf
    • https://cdn.shopify.com/s/files/1/0429/7680/5018/files/bhairava_tamil_movie_2017.pdf
    • https://cdn.shopify.com/s/files/1/0439/7318/1598/files/vabitusujaresevadipu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006429.bin
fb18eeadd25cf75ac8b872b412134a1c2a314b95076ca13a20152af3011f3c40
pdf-font-stream PDF embedded font (sfnt) at offset 0x6429 5384 bytes
font_01_sfnt_off00007649.bin
c6c57f86e028153189260c82f0ca86f27b6ce81f823d4685dde8f3883f1b76e5
pdf-font-stream PDF embedded font (sfnt) at offset 0x7649 10628 bytes
font_02_sfnt_off00009ad7.bin
81c7956dde52e5d908b0cea9d7ac892b31ef59a5fa024a2c105376ba8a0fbb11
pdf-font-stream PDF embedded font (sfnt) at offset 0x9AD7 16060 bytes