Malicious PDF — malware analysis report

Static analysis result for SHA-256 1f8c83bd339fb20f…

MALICIOUS

PDF

53.4 KB Created: 2020-08-20 04:28:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 848af08ea8300ec3b06e69e1fc4683db SHA-1: 8abce0319363f7872cbe061bb97a40ebb213ddef SHA-256: 1f8c83bd339fb20f03d498020f14b65c297156fe778d659c4f2f68ab2a45fdd0
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=pitu+app+chinese+apk'. Additionally, it exhibits a PDF link farm behavior, with numerous links to PDF files hosted on Shopify. The document body contains obfuscated text and the malicious URL, suggesting an attempt to disguise the malicious intent. The primary attack pattern involves redirecting users to malicious infrastructure.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=pitu+app+chinese+apk
    • http://files.creekviewvolleyball.com/uploads/1/3/1/8/131856039/9693390.pdf
    • http://files.sameems.com/uploads/1/3/0/8/130813694/gukitogo-puwuvepot-xagariligat.pdf
    • http://files.shop-with-bam.com/uploads/1/3/1/4/131437515/2024264.pdf
    • http://files.srrlsf.com/uploads/1/3/1/3/131380868/4f04903295aa5.pdf
    • https://cdn.shopify.com/s/files/1/0437/0530/3190/files/broiler_production_in_zimbabwe.pdf
    • https://cdn.shopify.com/s/files/1/0435/4513/3207/files/35508339457.pdf
    • https://cdn.shopify.com/s/files/1/0437/7968/6549/files/wonovonitapasumafubu.pdf
    • https://cdn.shopify.com/s/files/1/0428/9924/3174/files/jolikepapunanigeselusepov.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/dijovosulodomozov.pdf
    • https://cdn.shopify.com/s/files/1/0432/0493/5835/files/97164603256.pdf
    • https://cdn.shopify.com/s/files/1/0428/5281/0911/files/el_anarquismo_en_argentina.pdf
    • https://cdn.shopify.com/s/files/1/0430/9005/1221/files/42956291797.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/texirid.pdf
    • https://cdn.shopify.com/s/files/1/0433/4311/8495/files/eulerian_numbers_petersen.pdf
    • https://cdn.shopify.com/s/files/1/0436/9547/2793/files/jadejeronowesinedewulup.pdf
    • https://cdn.shopify.com/s/files/1/0430/7966/3765/files/57589104236.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000073aa.bin
aff11289bf87f92bc53c0e2abc335208e29b6db8a954e82fd0a5595ffa95d344
pdf-font-stream PDF embedded font (sfnt) at offset 0x73AA 2880 bytes
font_01_sfnt_off00007de8.bin
121ff9d5c3d060b12e07b79854b0e1e867e3fc446c1f7191afaf8980096be37b
pdf-font-stream PDF embedded font (sfnt) at offset 0x7DE8 4960 bytes
font_02_sfnt_off00008eba.bin
e214b229ba79fd06c6ba01c9c6aa5278c6d54cef5be999165aeac9a0020535ca
pdf-font-stream PDF embedded font (sfnt) at offset 0x8EBA 9864 bytes
font_03_sfnt_off0000b0bd.bin
8d9d240cef431a8debdd5586fa622fbb83554f222a0603859caa2ca0dc105e43
pdf-font-stream PDF embedded font (sfnt) at offset 0xB0BD 16744 bytes