Malicious PDF — malware analysis report

Static analysis result for SHA-256 f771fecde363a0b0…

MALICIOUS

PDF

66.8 KB Created: 2020-08-10 15:53:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6004f42a0dfc05f99533521e57fd8dc5 SHA-1: d820d3de8424a77e33429d1efefb00257c7130a2 SHA-256: f771fecde363a0b005e2bfcc4f8db7f4b1d9a9f87c620170adc641c52290e8e3
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a mass external link farm, with a primary malicious redirector URL embedded within the document body. This URL, https://ttraff.com/pify?keyword=arithmetic+sequence+word+problems+with+solutions+pdf, is designed to lure users into clicking it by appearing to offer solutions to arithmetic sequence word problems. The document's structure and embedded links strongly suggest a phishing or malware distribution attempt.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=arithmetic+sequence+word+problems+with+solutions+pdf
    • http://files.northrec.org/uploads/1/3/1/4/131437689/0c3afc7.pdf
    • http://files.ellenlisajones.co.uk/uploads/1/3/0/7/130776088/xewugigofi.pdf
    • http://gazuvuz.wainfleetskating.ca/uploads/1/3/2/3/132303382/ropavi_nafoz_totowifo_fufes.pdf
    • http://files.backyardheavens.com/uploads/1/3/1/3/131398022/gasov.pdf
    • http://debuwe.mariamorjane.com/uploads/1/3/0/7/130775219/e7e1ff6836a7.pdf
    • https://cdn.shopify.com/s/files/1/0431/9910/3136/files/1490041797.pdf
    • https://cdn.shopify.com/s/files/1/0429/6930/1151/files/vamupud.pdf
    • https://cdn.shopify.com/s/files/1/0440/0663/7726/files/jopisasosuni.pdf
    • https://cdn.shopify.com/s/files/1/0431/3487/7847/files/30774423008.pdf
    • https://cdn.shopify.com/s/files/1/0437/4993/3208/files/69702367443.pdf
    • https://cdn.shopify.com/s/files/1/0431/5476/8021/files/61425893572.pdf
    • https://cdn.shopify.com/s/files/1/0431/6823/5682/files/jiguretopiwelevik.pdf
    • https://cdn.shopify.com/s/files/1/0440/4926/8886/files/71683533307.pdf
    • https://cdn.shopify.com/s/files/1/0427/6230/5702/files/26029145228.pdf
    • https://cdn.shopify.com/s/files/1/0431/4818/1666/files/xagudawudupojamejiwifila.pdf
    • https://cdn.shopify.com/s/files/1/0436/0231/3373/files/bejokepuzivizuwif.pdf
    • https://cdn.shopify.com/s/files/1/0434/6042/7928/files/65223199345.pdf
    • https://cdn.shopify.com/s/files/1/0433/4203/7150/files/lowes_bluffton_sc.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000bc4c.bin
4aba2bb845853324476be69e5ed1bf4ff35002942389efac2b843cac1129f0e9
pdf-font-stream PDF embedded font (sfnt) at offset 0xBC4C 2828 bytes
font_01_sfnt_off0000c647.bin
e5a637b022dbb99d189960e64fc4cc2d27a4c2b6a5933c9d4aab7c76e0ca5d16
pdf-font-stream PDF embedded font (sfnt) at offset 0xC647 5532 bytes
font_02_sfnt_off0000d8fc.bin
daadec6e950c73937a05a9fab3e145d7fdc1b7debf41506f9773bc1ff2dd2920
pdf-font-stream PDF embedded font (sfnt) at offset 0xD8FC 9964 bytes