Malicious PDF — malware analysis report

Static analysis result for SHA-256 e58e8f440591c59d…

MALICIOUS

PDF

41.2 KB Created: 2020-08-15 18:30:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cd12489522702a1e4c9d08c7db3ef1f0 SHA-1: f80b022cb3b0c9e728449ee2b083fa82e8874559 SHA-256: e58e8f440591c59da59a81b98fefc1fdadddf09017d99ab07fdb83e59f046920
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link pointing to 'ttraff.com', which is associated with advance-fee scams. The document body, though heavily obfuscated, contains text related to 'Pradhan mantri schemes 2019 pdf' and the malicious URL. The presence of numerous embedded links, many hosted on Shopify, suggests a link farm designed to obscure the ultimate destination, with 'ttraff.com' being the primary malicious indicator.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wb?keyword=pradhan%20mantri%20schemes%202019%20pdf
    • http://debojup.mrsrodriguezsclass.com/uploads/1/3/1/6/131606490/poranolufojujexor.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/tizerosotusalasebix.pdf
    • https://cdn.shopify.com/s/files/1/0438/8877/1227/files/zotuzinomogu.pdf
    • https://cdn.shopify.com/s/files/1/0433/5442/3445/files/teachers_are_born_not_made.pdf
    • https://cdn.shopify.com/s/files/1/0431/7318/3637/files/80719850994.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/51191810805.pdf
    • https://cdn.shopify.com/s/files/1/0430/7006/2754/files/61144253038.pdf
    • https://cdn.shopify.com/s/files/1/0432/4071/8496/files/dalenikakez.pdf
    • https://cdn.shopify.com/s/files/1/0431/1390/6327/files/6256702495.pdf
    • https://cdn.shopify.com/s/files/1/0438/0255/8621/files/55418226575.pdf
    • https://cdn.shopify.com/s/files/1/0440/7217/3733/files/33020762390.pdf
    • https://cdn.shopify.com/s/files/1/0440/8056/2326/files/bachna_ae_hasseeno_songs.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000061e5.bin
81ec0f0a06b035b046f749e78df90bba7029bce3a7078cecba40584cff0b4df8
pdf-font-stream PDF embedded font (sfnt) at offset 0x61E5 5844 bytes
font_01_sfnt_off00007597.bin
c34fbe1aa7d67c0c549607ef8296fade4024ff9fd6da7b3621a7b8795cc50abf
pdf-font-stream PDF embedded font (sfnt) at offset 0x7597 10080 bytes