Malicious PDF — malware analysis report

Static analysis result for SHA-256 e3e8db8a9e52ecf1…

MALICIOUS

PDF

49.6 KB Created: 2020-08-16 23:16:40 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 09f5bcb13b5fa25404610679ad26464b SHA-1: 405bf250856f57f4e83d59c783adc993384f4812 SHA-256: e3e8db8a9e52ecf1e61e4ea2a4479c6aa9116964df2d90f06bb0df80f0dd6f5a
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains multiple embedded links, with one specifically pointing to a known malicious redirector. The document body text, though heavily obfuscated, contains phrases and URLs that suggest a lure for the user to click a download link. The presence of a 'download button' heuristic further supports this. The primary malicious URL identified is https://ttraff.ru/pify?keyword=action+plan+template, which likely serves as the initial stage of a malicious download or redirection chain.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=action+plan+template
    • http://files.sergetimmers.com/uploads/1/3/2/7/132712332/8928082.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/90067119925.pdf
    • https://cdn.shopify.com/s/files/1/0432/3698/2944/files/machine_learning_algorithms_jason_brownlee.pdf
    • https://cdn.shopify.com/s/files/1/0437/3735/0309/files/84488106990.pdf
    • https://cdn.shopify.com/s/files/1/0437/4387/1128/files/tobesisolubiborimune.pdf
    • https://cdn.shopify.com/s/files/1/0435/7586/9599/files/across_five_aprils_download.pdf
    • https://cdn.shopify.com/s/files/1/0433/1916/5086/files/80283446537.pdf
    • https://cdn.shopify.com/s/files/1/0433/5943/6951/files/caucasian_chalk_circle_questions_and_answers.pdf
    • https://cdn.shopify.com/s/files/1/0433/0668/0484/files/18655397162.pdf
    • https://cdn.shopify.com/s/files/1/0429/7395/4204/files/biotina_bula.pdf
    • https://cdn.shopify.com/s/files/1/0428/1607/7991/files/wugajaxufulozefine.pdf
    • https://cdn.shopify.com/s/files/1/0437/1097/2056/files/kitekutenabuparad.pdf
    • https://cdn.shopify.com/s/files/1/0434/0957/1990/files/vivimagufe.pdf
    • https://cdn.shopify.com/s/files/1/0438/6154/1014/files/76799043523.pdf
    • https://cdn.shopify.com/s/files/1/0430/5915/1009/files/69992279107.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000868f.bin
2e6fd1a2d723779b788759309796cccc00d276a856e905b0b9598a18a8f5ee24
pdf-font-stream PDF embedded font (sfnt) at offset 0x868F 4792 bytes
font_01_sfnt_off000096c0.bin
cc4b0de4f2f7ab672960c566432db06a82d7fe79255c2c7a3b76a9ddd6c2d425
pdf-font-stream PDF embedded font (sfnt) at offset 0x96C0 10308 bytes