Malicious PDF — malware analysis report

Static analysis result for SHA-256 e648ee0bac70e6fd…

MALICIOUS

PDF

65.5 KB Created: 2020-09-04 00:41:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7a3c5f205e055f0bbc324ee37b036343 SHA-1: 66b230cd217bbbdc052a4605576ac6023fc03bb5 SHA-256: e648ee0bac70e6fda14d4e1136bf395c70d2ea87dea5c97915c6c77eac55fb5e
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.me/wix?keyword=castrum+fluminis+normal+guide'. Additionally, another critical heuristic indicates a PDF link farm, with many external links, suggesting an attempt to distribute content or redirect users. The document body, though heavily obfuscated, contains the same malicious URL. The primary attack pattern involves luring the user to this malicious URL, which is likely a phishing or malware distribution gateway.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=castrum+fluminis+normal+guide
    • https://cdn.shopify.com/s/files/1/0440/3465/4358/files/soil_nematodes.pdf
    • https://cdn.shopify.com/s/files/1/0430/9850/5369/files/eclipse_java_cheat_sheet.pdf
    • https://cdn.shopify.com/s/files/1/0428/4504/4892/files/buwimi.pdf
    • https://cdn.shopify.com/s/files/1/0432/4638/7362/files/71769481167.pdf
    • https://cdn.shopify.com/s/files/1/0447/0757/8009/files/ballast_water_management_convention_2020.pdf
    • https://static.usrfiles.com/ugd/f6a907_77471f8aae0441a4a35e62758ad555d7.pdf
    • https://cdn.shopify.com/s/files/1/0431/6525/3789/files/kawakaburi_no_cherry.pdf
    • https://cdn.shopify.com/s/files/1/0430/9273/8201/files/ronuziwogexetemegaze.pdf
    • https://cdn.shopify.com/s/files/1/0432/9088/6299/files/serosugamijorogivo.pdf
    • https://static.usrfiles.com/ugd/e02969_6ef093376a9a4a8fa67bbe2c51b5f339.pdf
    • https://static.usrfiles.com/ugd/bb05c1_8a91280e619c467db3133cb0aefd4f14.pdf
    • https://static.usrfiles.com/ugd/576447_603487a002874ce1ad5caf03da568dbf.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009c44.bin
85f4091dbcea18bb987c1976a1eeb3b4f745a9427666473906f49a6deb64f19a
pdf-font-stream PDF embedded font (sfnt) at offset 0x9C44 4796 bytes
font_01_sfnt_off0000ace1.bin
0d011ca2ccbdbd3df78b9df9de395106ac540e430d906b23cf16b7e59f71f604
pdf-font-stream PDF embedded font (sfnt) at offset 0xACE1 5132 bytes
font_02_sfnt_off0000be37.bin
e661ea807126c13a1801d1009fde4ae93707c3213637c3a4d8aae9757bb73e7a
pdf-font-stream PDF embedded font (sfnt) at offset 0xBE37 10884 bytes
font_03_sfnt_off0000e353.bin
ea75db71c9df7250347a03039f742fcd189f5fc3f08964e696816fa8b5227073
pdf-font-stream PDF embedded font (sfnt) at offset 0xE353 16092 bytes