Malicious PDF — malware analysis report

Static analysis result for SHA-256 e46b110d44996f76…

MALICIOUS

PDF

71.1 KB Created: 2020-08-29 02:10:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 94ddf2eebaa05c7f659e297bfb97c7a0 SHA-1: 83f6874122be888ac169df0b1d17f3deb5c63c95 SHA-256: e46b110d44996f76bcff6af4dc615c98527148878852b5d75bf5a7a12a68ecf7
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/wix?keyword=libro+lo+negro+del+negro+gratis'. Another critical heuristic indicates a PDF link farm, with the primary benign-looking link being 'https://cdn.shopify.com/s/files/1/0433/4416/7064/files/8561372534.pdf'. The document body, though heavily obfuscated, contains the malicious URL, suggesting the document's purpose is to trick users into visiting this link, likely for phishing or to download further malicious content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=libro+lo+negro+del+negro+gratis
    • https://cdn.shopify.com/s/files/1/0433/4416/7064/files/8561372534.pdf
    • https://cdn.shopify.com/s/files/1/0430/0252/7895/files/newuvefuxomo.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/91146339154.pdf
    • https://cdn.shopify.com/s/files/1/0429/1608/5923/files/biochemical_engineering_fundamentals_james_e_bailey.pdf
    • https://cdn.shopify.com/s/files/1/0431/6368/0932/files/lowes_waycross_ga.pdf
    • https://cdn.shopify.com/s/files/1/0431/9812/0094/files/zufulapar.pdf
    • https://cdn.shopify.com/s/files/1/0434/8113/7316/files/arrl_satellite_handbook.pdf
    • https://cdn.shopify.com/s/files/1/0437/7231/3751/files/91190152818.pdf
    • https://cdn.shopify.com/s/files/1/0437/1218/4474/files/mavak.pdf
    • https://static.usrfiles.com/ugd/b8c837_2c3ccf94e199499b9bd50393b5a930bd.pdf
    • https://static.usrfiles.com/ugd/b8c837_28ee1430f79b46dc984a160ba83336f8.pdf
    • https://static.usrfiles.com/ugd/b8c837_c0d43d1519814115b32301c81109aad9.pdf
    • https://static.usrfiles.com/ugd/b8c837_1123d16fb5c3423fabb5776607bda751.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d41c.bin
a12eff9ee1e4b8d87ee52d3eef9ff5e2af2b84f69343d9dff4f0572bd7bde44f
pdf-font-stream PDF embedded font (sfnt) at offset 0xD41C 5072 bytes
font_01_sfnt_off0000e560.bin
ec9d5fe5bb110983654c7fd79ee33de210e8ed7bc3943cf002f9c6b153004a06
pdf-font-stream PDF embedded font (sfnt) at offset 0xE560 13016 bytes