Malicious PDF — malware analysis report

Static analysis result for SHA-256 e4866980f6ea6f4f…

MALICIOUS

PDF

48.0 KB Created: 2020-09-06 01:27:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 65f31daa764066d235f34215ea4d39e1 SHA-1: 901411edd86755e5307f9225904bb4e25f8cdff7 SHA-256: e4866980f6ea6f4f3da08cf37c3a3f69d32fe3b1655178ba24583bd01ddc33ad
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

This PDF file contains multiple embedded links, with one specifically pointing to a known malicious redirector. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external PDF links, suggesting an attempt to manipulate search engine results or distribute content widely. The 'SE_PASSWORD_ARCHIVE_LURE' heuristic suggests the document may be a precursor to delivering a password-protected archive, a common tactic to bypass security gateways. The primary malicious IOC is the redirector URL, which is likely the initial step in a phishing or scam operation.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=hello+brother+audio+song++com
    • https://cdn.shopify.com/s/files/1/0433/5822/4549/files/72256774038.pdf
    • https://cdn.shopify.com/s/files/1/0428/6709/7756/files/peluwewivudujop.pdf
    • https://cdn.shopify.com/s/files/1/0435/3599/0936/files/vigujabivap.pdf
    • https://cdn.shopify.com/s/files/1/0466/4990/1221/files/cg_police_exam_answer_sheet_2018.pdf
    • https://cdn.shopify.com/s/files/1/0434/0695/0557/files/schengen_visa_form_germany.pdf
    • https://cdn.shopify.com/s/files/1/0430/5072/9634/files/bypass_gstrico.pdf
    • https://cdn.shopify.com/s/files/1/0435/0361/6165/files/zakapinexivuwazazu.pdf
    • https://cdn.shopify.com/s/files/1/0434/3041/2437/files/markdown_comment_out.pdf
    • https://cdn.shopify.com/s/files/1/0437/8954/9726/files/69477398945.pdf
    • https://static.usrfiles.com/ugd/0df15e_6f5d807330f74267aedbb50018919657.pdf
    • https://static.usrfiles.com/ugd/e4ff69_4b461daf12844fd2bbce9f335f8eae27.pdf
    • https://cdn.shopify.com/s/files/1/0433/5173/6471/files/quien_invento_la_pasteurizacin.pdf
    • https://cdn.shopify.com/s/files/1/0429/2732/5343/files/auto_body_repair_order_forms.pdf
    • https://cdn.shopify.com/s/files/1/0429/2447/4531/files/33052192505.pdf
    • https://cdn.shopify.com/s/files/1/0430/8130/2167/files/subix.pdf
    • https://cdn.shopify.com/s/files/1/0431/1249/7305/files/95163811915.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007488.bin
b956cb499a109a82db58787d23e4a7af593166c4f8fbb533dabec04e89324f9d
pdf-font-stream PDF embedded font (sfnt) at offset 0x7488 5456 bytes
font_01_sfnt_off000086df.bin
6b28f5d464cc71aa2b9c0a17af28d5a7cb98102a560683efdb0a0a4dbb479b0f
pdf-font-stream PDF embedded font (sfnt) at offset 0x86DF 14160 bytes