Malicious PDF — malware analysis report

Static analysis result for SHA-256 fbcabd2ae737e6f1…

MALICIOUS

PDF

58.0 KB Created: 2020-08-08 00:49:28 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 617c8b2e6e2111addae85f29557b0778 SHA-1: 2af5f073dc7a2ecf9fea147de16016c3eafa5086 SHA-256: fbcabd2ae737e6f13990709bea015de3a51b3ae4ebe4a4fa39f17c4b8c4d5a9a
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains numerous embedded links, with a critical heuristic firing for a malicious redirector. The primary link directs to 'https://ttraff.com/pify?keyword=biology+notes+pdf+zambia', which is identified as a malicious redirector. Another heuristic indicates a PDF link farm, suggesting an attempt to distribute or host multiple malicious PDFs. The document body contains garbled text but includes the same redirector URL, reinforcing its malicious intent.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=biology+notes+pdf+zambia
    • http://files.backdoorfriendspurebredcatrescue.org/uploads/1/3/1/3/131380339/08ba5037fc41.pdf
    • http://files.adamsaada.com/uploads/1/3/2/8/132815882/8253279.pdf
    • http://files.globalnatives.org/uploads/1/3/1/4/131438079/tifebedipimazuxefu.pdf
    • http://files.blackberrykeep.com/uploads/1/3/2/7/132712661/54edda686.pdf
    • https://cdn.shopify.com/s/files/1/0431/3815/4657/files/davej.pdf
    • https://cdn.shopify.com/s/files/1/0433/6372/9557/files/julofesijezedi.pdf
    • https://cdn.shopify.com/s/files/1/0428/4832/1692/files/zibetiduxeb.pdf
    • https://cdn.shopify.com/s/files/1/0429/5032/8486/files/alimentos_ricos_vitamina_c.pdf
    • https://cdn.shopify.com/s/files/1/0433/8122/7672/files/penoroba.pdf
    • https://cdn.shopify.com/s/files/1/0427/7207/0556/files/xanonugemijutiz.pdf
    • https://cdn.shopify.com/s/files/1/0449/8941/5583/files/quran_word_by_word_urdu_translation_para_30.pdf
    • https://cdn.shopify.com/s/files/1/0430/2651/4077/files/xazora.pdf
    • https://cdn.shopify.com/s/files/1/0450/4325/3406/files/geometria_angulos_y_triangulos.pdf
    • https://cdn.shopify.com/s/files/1/0431/7020/1760/files/88607557761.pdf
    • https://cdn.shopify.com/s/files/1/0432/2702/1480/files/jilidozebosodajovebuf.pdf
    • https://cdn.shopify.com/s/files/1/0431/9212/3560/files/ap_computer_science_practice_test.pdf
    • https://cdn.shopify.com/s/files/1/0440/1538/6789/files/beachbody_21_day_fix_calendar.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007c1b.bin
4bc01e55af79b10055a631b627477ee1be8809645365c6eb09435c5d5b9b4b0b
pdf-font-stream PDF embedded font (sfnt) at offset 0x7C1B 5392 bytes
font_01_sfnt_off00008e6b.bin
1a3915a2681f82f306a58a2993ad12c43be0c91fcc305984170bfebf7124653e
pdf-font-stream PDF embedded font (sfnt) at offset 0x8E6B 13012 bytes
font_02_sfnt_off0000b679.bin
9cb0650af5bdb2e8593988a361a40fe1030b61ea25d8fce7fab67310e0b1f9a7
pdf-font-stream PDF embedded font (sfnt) at offset 0xB679 16352 bytes
font_03_sfnt_off0000cc01.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0xCC01 4324 bytes