Malicious PDF — malware analysis report

Static analysis result for SHA-256 e015089eb2962395…

MALICIOUS

PDF

172.3 KB Created: 2020-08-03 05:20:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3e245aab22ede03d9877f13761d6c865 SHA-1: 871dae159322fabd7fac54ef864e9c3b5de6b5ad SHA-256: e015089eb2962395452bffe836e421345adc264a8a4d3d3e34f55bfe6ad64dac
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a critical heuristic firing indicating a malicious redirector link. The embedded URL points to 'ttraff.cc', which is known malicious infrastructure. The document body, though heavily obfuscated, contains the same URL, suggesting the primary intent is to redirect the user to this malicious site. No scripts were extracted from this sample.

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=iphone+device+name
    • http://files.spasiloam.com/uploads/1/3/1/0/131070688/wukusipesenur_rogerot_xoxalofoli_bubax.pdf
    • http://files.stbartshighsprings.org/uploads/1/3/1/4/131454523/3860767.pdf
    • http://files.haddingtongarden.com/uploads/1/3/0/7/130739918/104605.pdf
    • http://files.buffalohats.com/uploads/1/3/0/9/130969448/30967c.pdf
    • http://files.lotuspoints.com/uploads/1/3/1/4/131453674/013cabb898e.pdf
    • https://cdn.shopify.com/s/files/1/0436/9163/8934/files/https_192._168._l._254._254.pdf
    • https://cdn.shopify.com/s/files/1/0431/1931/3062/files/6500946039.pdf
    • https://cdn.shopify.com/s/files/1/0430/8759/3632/files/29129908747.pdf
    • https://cdn.shopify.com/s/files/1/0432/8180/9558/files/noel_jones_manual_for_preachers.pdf
    • https://cdn.shopify.com/s/files/1/0431/0263/4148/files/31035515983.pdf
    • https://cdn.shopify.com/s/files/1/0431/4886/9786/files/pobobop.pdf
    • https://cdn.shopify.com/s/files/1/0434/7405/9430/files/90975076247.pdf
    • https://cdn.shopify.com/s/files/1/0433/6327/0815/files/31423895192.pdf
    • https://cdn.shopify.com/s/files/1/0437/7015/1061/files/lozaj.pdf
    • https://cdn.shopify.com/s/files/1/0432/6647/4139/files/92377467759.pdf
    • https://cdn.shopify.com/s/files/1/0438/3657/1805/files/12561717543.pdf
    • https://cdn.shopify.com/s/files/1/0430/2965/9805/files/lowes_peach_orchard_rd.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000229b7.bin
f160e0e5bf19741cc6a70b4c5a3e857839171f509371de8ee9ff5fb9d836f003
pdf-font-stream PDF embedded font (sfnt) at offset 0x229B7 4360 bytes
font_01_sfnt_off00023906.bin
412b9c4da28522a07cf87bf8a2d7ed6ac23e776c95beaf6766635b3d018fc623
pdf-font-stream PDF embedded font (sfnt) at offset 0x23906 4712 bytes
font_02_sfnt_off000248ce.bin
8df89d2bdddccd66a92546b70343f762809a512e8864900f3968931285cd1420
pdf-font-stream PDF embedded font (sfnt) at offset 0x248CE 17776 bytes
font_03_sfnt_off0002802f.bin
2173a1880e9f774f759393e7d0d28dda91d04d8a3eae6bea41b822770b343b90
pdf-font-stream PDF embedded font (sfnt) at offset 0x2802F 16060 bytes
font_04_sfnt_off000294c6.bin
9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x294C6 4324 bytes