Malicious PDF — malware analysis report

Static analysis result for SHA-256 42f892dcad12a9ea…

MALICIOUS

PDF

39.2 KB Created: 2020-08-04 18:50:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7a093616e39bd6c8033b8bce8be24a7b SHA-1: 2c9c1bc98b7f7412fe6cc4f2131b339b7eff5b5d SHA-256: 42f892dcad12a9ea11ed3455261a6b799816fdf766213b161ea54f7895eefd44
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=microbiologia+veterin%25C3%25A1ria+essencial+pdf'. This indicates the document is designed to redirect users to malicious infrastructure. Additionally, a PDF SEO link farm heuristic was triggered, suggesting the PDF is part of a larger scheme to generate traffic or distribute content through numerous links. The document body contains garbled text but includes the malicious URL and several Shopify URLs, one of which is identified as a redirector.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=microbiologia+veterin%25C3%25A1ria+essencial+pdf
    • http://files.uvicscuba.com/uploads/1/3/1/1/131164236/7616194.pdf
    • http://files.bathurstfamilytherapy.com/uploads/1/3/0/8/130814110/borome-relakekigo-relimoka-xakujepakejumer.pdf
    • http://files.devils-trumpet.com/uploads/1/3/2/6/132695694/1629948.pdf
    • https://cdn.shopify.com/s/files/1/0429/8027/8426/files/talugumegavubad.pdf
    • https://cdn.shopify.com/s/files/1/0434/3057/6278/files/94808520621.pdf
    • https://cdn.shopify.com/s/files/1/0431/9143/5422/files/vasarijekujokebeguxujin.pdf
    • https://cdn.shopify.com/s/files/1/0433/9620/2661/files/53116232990.pdf
    • https://cdn.shopify.com/s/files/1/0429/0379/7913/files/peginawenilakisemiwufo.pdf
    • https://cdn.shopify.com/s/files/1/0432/8026/9477/files/47205703385.pdf
    • https://cdn.shopify.com/s/files/1/0430/8451/3440/files/wogokobenetejomonebuvawem.pdf
    • https://cdn.shopify.com/s/files/1/0440/1748/3934/files/fezuf.pdf
    • https://cdn.shopify.com/s/files/1/0437/8158/7095/files/nekibukirixupiz.pdf
    • https://cdn.shopify.com/s/files/1/0429/1595/4847/files/memivadumerufepukozit.pdf
    • https://cdn.shopify.com/s/files/1/0437/0749/8647/files/29748999875.pdf
    • https://cdn.shopify.com/s/files/1/0437/4098/7543/files/mawonapofofotut.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000048f9.bin
ba62ce2ea0a0c960e400fe29a6692ecdef26842a919e1608a3df960707850bd6
pdf-font-stream PDF embedded font (sfnt) at offset 0x48F9 5552 bytes
font_01_sfnt_off00005b63.bin
6b537104e48a6555e3b2d6dcd087f4460c594182a6933a7034c3ae6b88323214
pdf-font-stream PDF embedded font (sfnt) at offset 0x5B63 12020 bytes
font_02_sfnt_off00007f85.bin
ff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F85 4324 bytes