Malicious PDF — malware analysis report

Static analysis result for SHA-256 1f7b293ff389f5e6…

MALICIOUS

PDF

50.5 KB Created: 2020-08-10 03:39:40 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 81ee3316da9d9191b12e61c8fa7628f9 SHA-1: cddc16c4f2ab5619362f7bbc4fe278883d54e296 SHA-256: 1f7b293ff389f5e62b699fd83e57074c712e1875089210282197beb912e16472
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, many of which point to a redirector service. The document body text and embedded links suggest a lure for downloading potentially malicious files disguised as documentation. The primary malicious IOC is the redirector URL, which likely leads to further stages of the attack. The presence of numerous external links indicates a link farm SEO tactic to improve search engine visibility for malicious content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=sixth+sense+technology+documentation+pdf+free+download
    • http://files.animalhousejanitorial.net/uploads/1/3/0/7/130740571/399624b37bac32.pdf
    • http://files.mahoningcountyretiredteachers.com/uploads/1/3/1/4/131406491/sowedej.pdf
    • http://files.discountfootballshirtframing.net/uploads/1/3/0/9/130969489/1107900.pdf
    • http://files.policetrailer.com/uploads/1/3/1/6/131606859/140011f86695377.pdf
    • http://files.adelaide-pilates.com/uploads/1/3/0/7/130739761/zijupepojumoviziwese.pdf
    • https://cdn.shopify.com/s/files/1/0430/7173/3917/files/18784130635.pdf
    • https://cdn.shopify.com/s/files/1/0432/3019/9966/files/28899417639.pdf
    • https://cdn.shopify.com/s/files/1/0430/9739/1261/files/fireproof_full_movie.pdf
    • https://cdn.shopify.com/s/files/1/0427/7963/9967/files/pumomiwezepesaxoreromow.pdf
    • https://cdn.shopify.com/s/files/1/0435/3982/4799/files/32805518823.pdf
    • https://cdn.shopify.com/s/files/1/0429/8906/0259/files/the_strength_training_anatomy_workout_volume_2.pdf
    • https://cdn.shopify.com/s/files/1/0429/7077/5706/files/41427164187.pdf
    • https://cdn.shopify.com/s/files/1/0431/4988/5606/files/always_on_top_chrome.pdf
    • https://cdn.shopify.com/s/files/1/0433/7431/3633/files/22272725124.pdf
    • https://cdn.shopify.com/s/files/1/0435/4015/2479/files/knowledge_processing_and_applied_artificial_intelligence.pdf
    • https://cdn.shopify.com/s/files/1/0430/4768/2201/files/sarpino_s_pizza_menu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007a6f.bin
2a6fc6b356c1b9d73f7ae16ac90627d662ef879e32c9e861986f18eb4afd328c
pdf-font-stream PDF embedded font (sfnt) at offset 0x7A6F 5936 bytes
font_01_sfnt_off00008e89.bin
a36eee06fef6ce219692c4ec918276ac99413e4fd1e3666e4031624f9289d620
pdf-font-stream PDF embedded font (sfnt) at offset 0x8E89 1800 bytes
font_02_sfnt_off00009716.bin
b4e7137f9adbde760dd51d11ee2e982ef589d36d307fc759fe5838a41e044985
pdf-font-stream PDF embedded font (sfnt) at offset 0x9716 10824 bytes