Malicious PDF — malware analysis report

Static analysis result for SHA-256 7593e732ec9d5147…

MALICIOUS

PDF

48.2 KB Created: 2020-08-01 12:08:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 621a9bebde3fdcac2a84d0ce5879f317 SHA-1: 29335c7c6b05b9fc6174539214c96099f538b81c SHA-256: 7593e732ec9d51472d15ff01e5ad7f5fce6fdd0b3f51006c9bb3af7d69c8aa3b
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.cc/pify?keyword=linux+du+command'. This URL is presented within the document body, disguised as information about the Linux 'du' command, to entice users to click. The file also exhibits characteristics of a link farm, with numerous embedded links, many pointing to Shopify domains, likely for SEO manipulation or to obscure the malicious redirector. The primary malicious IOC is the ttraff.cc redirector, which is known to lead to further malicious content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=linux+du+command
    • http://files.kuminailbeautybar.com/uploads/1/3/0/8/130874101/c5a749994c95a.pdf
    • http://files.holisticimpactfoundation.org/uploads/1/3/0/7/130739480/tolosidimamirol.pdf
    • http://files.restonsusedbookshop.com/uploads/1/3/0/7/130775400/tefozefepokivapag.pdf
    • https://cdn.shopify.com/s/files/1/0434/6901/3158/files/42218645175.pdf
    • https://cdn.shopify.com/s/files/1/0427/4877/2519/files/56179067714.pdf
    • https://cdn.shopify.com/s/files/1/0439/4038/0840/files/9199038712.pdf
    • https://cdn.shopify.com/s/files/1/0431/5326/0700/files/muripuvonawuv.pdf
    • https://cdn.shopify.com/s/files/1/0428/1604/5222/files/liketajarobidudepozovog.pdf
    • https://cdn.shopify.com/s/files/1/0432/0280/5917/files/zuxaxajudov.pdf
    • https://cdn.shopify.com/s/files/1/0432/5851/1510/files/wewamiredaxuwevopuvag.pdf
    • https://cdn.shopify.com/s/files/1/0432/8259/6004/files/53598799223.pdf
    • https://cdn.shopify.com/s/files/1/0437/2529/1671/files/61533070150.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/faxusumowavunisipor.pdf
    • https://cdn.shopify.com/s/files/1/0439/4899/8811/files/toro_6._75_149cc_manual.pdf
    • https://cdn.shopify.com/s/files/1/0435/3854/6840/files/xejepukixixoji.pdf
    • https://cdn.shopify.com/s/files/1/0431/2111/5298/files/2306369690.pdf
    • https://cdn.shopify.com/s/files/1/0430/6694/9786/files/58403612916.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000063c4.bin
7e671c4cd4e53e952b9168a5c4b66f9e91c48241f23bd005c58070e1e68c3017
pdf-font-stream PDF embedded font (sfnt) at offset 0x63C4 4788 bytes
font_01_sfnt_off00007402.bin
a43f9484fba44bb1a4982c4870e3e137e64e324d9083ac1250accf5d721bcdd9
pdf-font-stream PDF embedded font (sfnt) at offset 0x7402 12436 bytes
font_02_sfnt_off00009cd5.bin
43fd6e4953e7c160a9c7f0d2034052d93a1101a8b4400dda15446878f8a807ac
pdf-font-stream PDF embedded font (sfnt) at offset 0x9CD5 16244 bytes