Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8c465665dd753f4…

MALICIOUS

PDF

162.2 KB Created: 2020-08-10 07:25:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7079f8527c8064bfff3a67fb45fcd8ad SHA-1: 2840b21544de8d70091adb726aab953dd4662a72 SHA-256: e8c465665dd753f46356ce679b492f4a15087ea0818670ddb5e637e2c9e3b3ac
68 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF file contains a critical heuristic firing indicating it links to known malicious redirector infrastructure. The embedded URL, https://ttraff.com/pify?keyword=oceanography+notes+pdf+upsc, is the primary indicator of malicious activity. The document body, though heavily obfuscated, contains this URL, suggesting the document's purpose is to lure the user to this external site. No scripts were extracted, and the file type is PDF, pointing towards a phishing or malware delivery attempt via a malicious link.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=oceanography+notes+pdf+upsc
    • http://files.choicesarchitecture.com/uploads/1/3/0/8/130813095/busugametilavo.pdf
    • http://files.musicmattersintheuk.com/uploads/1/3/0/8/130874058/e686a9f4.pdf
    • http://files.kitchen2boardroom.com/uploads/1/3/1/3/131398419/2838550.pdf
    • http://files.photosbycalley.com/uploads/1/3/0/7/130739284/nikafakinu_gokoxanogepokiv_fozusuli_xositorafaxemig.pdf
    • http://files.coolmetoday.com/uploads/1/3/1/3/131398174/5998435.pdf
    • https://cdn.shopify.com/s/files/1/0431/8386/6018/files/3089550737.pdf
    • https://cdn.shopify.com/s/files/1/0438/0744/1053/files/aptitude_questions_asked_in_interviews.pdf
    • https://cdn.shopify.com/s/files/1/0435/8170/2303/files/wacom_bamboo_cth-_470.pdf
    • https://cdn.shopify.com/s/files/1/0433/7054/5308/files/tidoxatigobezelebegabukal.pdf
    • https://cdn.shopify.com/s/files/1/0432/7804/1244/files/bodinosilitemalujububom.pdf
    • https://cdn.shopify.com/s/files/1/0430/8369/4247/files/buku_akuntansi_dasar_untuk_pemula.pdf
    • https://cdn.shopify.com/s/files/1/0432/5366/1864/files/the_company_cheat_codes.pdf
    • https://cdn.shopify.com/s/files/1/0434/2949/4936/files/jixumexaparulixibimet.pdf
    • https://cdn.shopify.com/s/files/1/0432/1456/9640/files/11364938158.pdf
    • https://cdn.shopify.com/s/files/1/0437/0032/2458/files/65115102611.pdf
    • https://cdn.shopify.com/s/files/1/0434/8978/8069/files/gre_analytical_writing_topics.pdf
    • https://cdn.shopify.com/s/files/1/0435/2904/4119/files/47200528452.pdf
    • https://cdn.shopify.com/s/files/1/0430/1137/5267/files/kisalunafenarovux.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00022f1e.bin
2fe47eba176cdd8d813e9362e809f2b3276c086e45fa0c00284189f620ab9582
pdf-font-stream PDF embedded font (sfnt) at offset 0x22F1E 5516 bytes
font_01_sfnt_off000241e0.bin
57d11b2d8a8d403ff587b5cb729b953b2c48fb2b847581f9a909c102efac53f9
pdf-font-stream PDF embedded font (sfnt) at offset 0x241E0 10356 bytes
font_02_sfnt_off00026582.bin
7c46bdd5995085f1b667db334183647021a114cb1e9de6240a6a2392c095f0cc
pdf-font-stream PDF embedded font (sfnt) at offset 0x26582 16144 bytes