Malicious PDF — malware analysis report

Static analysis result for SHA-256 1f0995ebb0f3aefc…

MALICIOUS

PDF

50.1 KB Created: 2020-08-11 23:07:03 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5095f9c7650df2bb1da6905914eb503b SHA-1: 8d2eca27a2cb508fabb03bef5fe541c4312187a4 SHA-256: 1f0995ebb0f3aefc291579400550c9975b13bb9c89449925e2d0de45810340c5
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a mass external link farm, with many links pointing to benign Shopify URLs but one critical link redirecting to a known malicious domain. The document body text, though garbled, contains the URL that is also present in the PDF's link annotation, suggesting the user is intended to click this link. The primary malicious IOC is the redirector URL.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=electrical+engineering+mcqs+by+m+handa+pdf+free+download
    • http://files.janezellmusic.com/uploads/1/3/1/4/131483275/lirejibivifoz.pdf
    • http://files.caitlindemeyere.ca/uploads/1/3/0/8/130874612/df4d54550cb3.pdf
    • http://marutopa.myviewpointon.org/uploads/1/3/1/3/131382406/xemikebel_zafiwezel_jibovixafu_xadaxiref.pdf
    • http://pujug.blackfoxllc.com/uploads/1/3/2/3/132303189/jipigavozibojumomez.pdf
    • https://cdn.shopify.com/s/files/1/0429/2263/9527/files/tigezemudevujinokit.pdf
    • https://cdn.shopify.com/s/files/1/0434/4024/2840/files/89034026116.pdf
    • https://cdn.shopify.com/s/files/1/0430/2631/7473/files/77041819644.pdf
    • https://cdn.shopify.com/s/files/1/0437/8427/4069/files/58371266381.pdf
    • https://cdn.shopify.com/s/files/1/0439/6823/3630/files/71716445440.pdf
    • https://cdn.shopify.com/s/files/1/0429/7208/6423/files/56340933769.pdf
    • https://cdn.shopify.com/s/files/1/0448/5827/8050/files/biochemistry_study_guide_answer_key.pdf
    • https://cdn.shopify.com/s/files/1/0428/2561/3475/files/anti_monopoly_law_china.pdf
    • https://cdn.shopify.com/s/files/1/0434/6255/7856/files/24532952726.pdf
    • https://cdn.shopify.com/s/files/1/0438/4056/9494/files/fowediwipowir.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/gimuwuwizarisatin.pdf
    • https://cdn.shopify.com/s/files/1/0428/0870/5187/files/celi_3_libro.pdf
    • https://cdn.shopify.com/s/files/1/0432/7093/0600/files/point_biserial_correlation.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000629d.bin
6b1d06e59f236d35d553dc37fdf383c5351f36d65efe4d6250d5b39d31f06258
pdf-font-stream PDF embedded font (sfnt) at offset 0x629D 5772 bytes
font_01_sfnt_off00007605.bin
2d35fe1b112251630f6c3e185fb4bf58c6327cea99f60afab3ca0473214b5b30
pdf-font-stream PDF embedded font (sfnt) at offset 0x7605 2116 bytes
font_02_sfnt_off00007fd1.bin
6ed44261bd9143721b8e29ce364b5f65303a8769b6087462790b44d9cb917733
pdf-font-stream PDF embedded font (sfnt) at offset 0x7FD1 14152 bytes
font_03_sfnt_off0000abd3.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0xABD3 4324 bytes