Malicious PDF — malware analysis report

Static analysis result for SHA-256 e58819684b0cf515…

MALICIOUS

PDF

51.8 KB Created: 2020-08-03 12:38:41 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9356c276218928363466f15c55890adb SHA-1: 50ac1ea93286656fd0d40a9deb75156293742970 SHA-256: e58819684b0cf515226ec6b0e53d23c0163469c02d8493e42e612654ad95524a
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a mass of external links, many of which are SEO-optimized to appear as legitimate document downloads. One critical heuristic identified a link to a known malicious redirector, ttraff.cc, which is used to obscure the final malicious destination. The document body itself contains the malicious URL, suggesting the intent is to trick users into clicking through to a potentially harmful site.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=fi+dhilal+al+quran+arabic+pdf+download
    • http://files.worldwarc.ca/uploads/1/3/2/6/132680986/917b154c60c8.pdf
    • http://files.thepixelempire.net/uploads/1/3/1/3/131398231/firomuvanew_futepivo.pdf
    • http://files.velocitytraining.org/uploads/1/3/1/4/131452949/019a46026.pdf
    • http://files.tinagutierrezartsphotography.com/uploads/1/3/0/7/130775383/remax-taxopugazaledu-fuluxibejurifuj-lavosiraleset.pdf
    • https://cdn.shopify.com/s/files/1/0431/8996/0865/files/84421378117.pdf
    • https://cdn.shopify.com/s/files/1/0429/5101/6614/files/12180943203.pdf
    • https://cdn.shopify.com/s/files/1/0435/2330/9727/files/65002330337.pdf
    • https://cdn.shopify.com/s/files/1/0432/8331/6891/files/walmart_balance_sheets.pdf
    • https://cdn.shopify.com/s/files/1/0431/5168/7848/files/desosaloniwirogeg.pdf
    • https://cdn.shopify.com/s/files/1/0429/7365/9290/files/55670999222.pdf
    • https://cdn.shopify.com/s/files/1/0431/0538/6647/files/senipir.pdf
    • https://cdn.shopify.com/s/files/1/0433/1087/4777/files/wubarapopig.pdf
    • https://cdn.shopify.com/s/files/1/0428/2518/7491/files/rosadewi.pdf
    • https://cdn.shopify.com/s/files/1/0435/5375/1189/files/cat_416_backhoe_manual.pdf
    • https://cdn.shopify.com/s/files/1/0428/4874/7676/files/sawodipututuzodopusi.pdf
    • https://cdn.shopify.com/s/files/1/0434/0622/9654/files/66496508212.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off0000a5ee.bin
ac494c34a398ecbbfe285b5837751827d7f10ff3bf43c884800bc5793e5521f4
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xA5EE 17368 bytes
font_00_sfnt_off000067ea.bin
786290c19a4f8e2b6021c4ae77960c15484137f160498028cb9dcaf518cd78f1
pdf-font-stream PDF embedded font (sfnt) at offset 0x67EA 5376 bytes
font_01_sfnt_off00007a3c.bin
4d86463cd637b640c05f52cf6338643fc49caafa142d663136f3ea72763505fa
pdf-font-stream PDF embedded font (sfnt) at offset 0x7A3C 13972 bytes