Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef1e90ddc68da738…

MALICIOUS

PDF

54.7 KB Created: 2020-07-31 05:14:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c33144cd17913398e3c2a7c4b2726cb6 SHA-1: 2a1d7deac37e39bc6627a3f843730bae013748fd SHA-256: ef1e90ddc68da738d5f9d8bdcbaa12f0acc429e6ad9bbfb381e312b9a9792727
162 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a link to a known malicious redirector, ttraff.ru, disguised with keywords related to a spiritual stotram. This indicates a phishing or malware delivery attempt. The presence of a 'LOLBin run command' heuristic suggests that the document may also contain embedded instructions or scripts to execute malicious commands, potentially involving tools like PowerShell, to further the attack. The document body itself is heavily obfuscated and unreadable, providing no further context.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visible LOLBin command execution instruction high SE_LOLBIN_RUN_COMMAND
    Document contains instructions or visible command text involving Windows script/execution tools such as PowerShell, mshta, cmd, rundll32, or regsvr32
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=shani+graha+narasimha+stotram+pdf
    • http://files.stgall.com/uploads/1/3/1/4/131407952/lemumudeku.pdf
    • http://files.lotusleafyoga.co.uk/uploads/1/3/0/7/130738512/zomatuwovatubigiwijo.pdf
    • http://files.curlymo.com/uploads/1/3/0/7/130739593/pevakenuguv.pdf
    • https://cdn.shopify.com/s/files/1/0440/6712/7446/files/1363743829.pdf
    • https://cdn.shopify.com/s/files/1/0429/6255/0940/files/9983825509.pdf
    • https://cdn.shopify.com/s/files/1/0428/3393/6547/files/nuselejebifulozameka.pdf
    • https://cdn.shopify.com/s/files/1/0430/7045/5965/files/benerekapezizije.pdf
    • https://cdn.shopify.com/s/files/1/0429/5039/4019/files/40866299856.pdf
    • https://cdn.shopify.com/s/files/1/0428/2590/8383/files/52906265240.pdf
    • https://cdn.shopify.com/s/files/1/0438/3778/4229/files/21058371639.pdf
    • https://cdn.shopify.com/s/files/1/0431/9245/1232/files/85277190504.pdf
    • https://cdn.shopify.com/s/files/1/0432/8957/5588/files/93556894747.pdf
    • https://cdn.shopify.com/s/files/1/0429/5829/1093/files/80551950319.pdf
    • https://cdn.shopify.com/s/files/1/0435/6957/8147/files/35332666760.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009a70.bin
a48fcc11261bca30b2f3e130b64b5bbe3d65dfb56de1f30eeefd92ac0c848711
pdf-font-stream PDF embedded font (sfnt) at offset 0x9A70 5196 bytes
font_01_sfnt_off0000abd4.bin
c143bd4637bd7fe75327aff5c42c189529e4f865db7762c93979c67c13aaf192
pdf-font-stream PDF embedded font (sfnt) at offset 0xABD4 9892 bytes