Malicious PDF — malware analysis report

Static analysis result for SHA-256 3376843207832aa4…

MALICIOUS

PDF

51.6 KB Created: 2020-08-21 18:21:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6d792aa49dfdd150e0152354be7b6b52 SHA-1: 5329d6d8b4365302f9b8da7a481ee7102693d7a3 SHA-256: 3376843207832aa4218692e884ecebf931cd007368be38157051871571e9a373
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, many of which point to a link farm hosted on Shopify. One of the primary links directs to a known malicious redirector. The document body, though heavily obfuscated, contains the same URL as the malicious redirector, suggesting an attempt to lure users to malicious content. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=white+bump+forming+around+nose+piercing
    • http://files.nightingaletrio.com/uploads/1/3/1/4/131438202/segizowizere-memeno-fadoz.pdf
    • http://files.moreways2makemoney.com/uploads/1/3/2/6/132683330/01c4962.pdf
    • http://tufugo.addarcenter.com/uploads/1/3/1/4/131437850/rorewemima.pdf
    • http://zagemebe.mytjsdeli.com/uploads/1/3/1/4/131483083/5754736.pdf
    • https://cdn.shopify.com/s/files/1/0430/5059/8562/files/alif_novel_episode_10_download.pdf
    • https://cdn.shopify.com/s/files/1/0429/2391/7475/files/janosilureba.pdf
    • https://cdn.shopify.com/s/files/1/0437/1087/3765/files/50955253403.pdf
    • https://cdn.shopify.com/s/files/1/0427/9474/6023/files/ziwubixuxor.pdf
    • https://cdn.shopify.com/s/files/1/0432/8387/3942/files/53202768753.pdf
    • https://cdn.shopify.com/s/files/1/0427/6197/8023/files/how_to_make_beetroot_soup_in_minecraft.pdf
    • https://cdn.shopify.com/s/files/1/0436/7400/9753/files/centurylink_wifi_password.pdf
    • https://cdn.shopify.com/s/files/1/0429/0379/7913/files/word_cookies_answers_creme_brulee_05.pdf
    • https://cdn.shopify.com/s/files/1/0428/9911/2095/files/20463386009.pdf
    • https://cdn.shopify.com/s/files/1/0428/6559/0438/files/judivedulesu.pdf
    • https://cdn.shopify.com/s/files/1/0432/9740/7126/files/kivojivaniruditufugij.pdf
    • https://cdn.shopify.com/s/files/1/0429/7365/9290/files/wopavavevemotasotosazege.pdf
    • https://cdn.shopify.com/s/files/1/0435/9317/1103/files/lexique_informatique_anglais_franais.pdf
    • https://cdn.shopify.com/s/files/1/0450/2867/1646/files/cessna_caravan_operating_costs.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007e0f.bin
371b8eb22a5f8a278cc5f4f74514f2d89de1107625a53bc822da286925033217
pdf-font-stream PDF embedded font (sfnt) at offset 0x7E0F 5572 bytes
font_01_sfnt_off000090d6.bin
748771cbceab57eb1aab0d6bdf15f4b766e41289f22e53169a9156c1e8259a2c
pdf-font-stream PDF embedded font (sfnt) at offset 0x90D6 9884 bytes
font_02_sfnt_off0000b2a3.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0xB2A3 4324 bytes