Malicious PDF — malware analysis report

Static analysis result for SHA-256 fe0b4b327c6779bd…

MALICIOUS

PDF

37.0 KB Created: 2020-09-02 04:24:59 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: dd9d1155c842cad0df9874ee7740fbe5 SHA-1: f75b0aa898d30f5028a3bcdafea29f12111a8e1f SHA-256: fe0b4b327c6779bd4580f4d683669cd7270a361f24405cf557e26f5b873f936b
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link pointing to 'https://ttraff.club/wix?keyword=aplikasi+android+device+manager+apk'. It also exhibits characteristics of a PDF link farm, with numerous links to external PDFs, many hosted on cdn.shopify.com. The presence of a 'Password-protected archive handoff' heuristic suggests the document is intended to trick the user into downloading an encrypted file, likely containing malware, after providing password instructions. The document body contains obfuscated text and the malicious URL, reinforcing the lure.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=aplikasi+android+device+manager+apk
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/2033782386.pdf
    • https://cdn.shopify.com/s/files/1/0433/5101/5579/files/maryland_state_employee_salaries_2018.pdf
    • https://cdn.shopify.com/s/files/1/0430/9073/9361/files/lagukos.pdf
    • https://cdn.shopify.com/s/files/1/0437/8814/0696/files/39652616617.pdf
    • https://cdn.shopify.com/s/files/1/0433/1916/5086/files/rimaxitorolaxa.pdf
    • https://static.usrfiles.com/ugd/9904c2_c80a88e85c61467f8413d9e8722534b1.pdf
    • https://static.usrfiles.com/ugd/f459ea_e313e286d460401f859325c8a1aaf2ee.pdf
    • https://static.usrfiles.com/ugd/9b7d8a_e4f2c0018f48461faeb4d0afe119fe17.pdf
    • https://static.usrfiles.com/ugd/a18aa6_6b39ab92ec524d43814f831c4952b073.pdf
    • https://static.usrfiles.com/ugd/a4d998_79f38eb7419c4369a9cf7c7f6580af79.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/dilos.pdf
    • https://cdn.shopify.com/s/files/1/0437/6189/3533/files/39147984708.pdf
    • https://cdn.shopify.com/s/files/1/0435/9861/0591/files/all_devotional_songs_free.pdf
    • https://cdn.shopify.com/s/files/1/0431/6508/9941/files/git_permission_denied_publickey.pdf
    • https://cdn.shopify.com/s/files/1/0428/1945/3095/files/99576965378.pdf
    • https://cdn.shopify.com/s/files/1/0433/8286/6083/files/wonasiroziwur.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000053c8.bin
0078641af5524ed6059f2a0c7a7880fe8c640df7e9d4ea8ad78e89eacf7b1de8
pdf-font-stream PDF embedded font (sfnt) at offset 0x53C8 5504 bytes
font_01_sfnt_off00006670.bin
6344b5f9b3ff9310859bd443e3d293bc9768536f42bb99e5dccdda036a5b3205
pdf-font-stream PDF embedded font (sfnt) at offset 0x6670 9544 bytes