Malicious PDF — malware analysis report

Static analysis result for SHA-256 7b58f731d77f231f…

MALICIOUS

PDF

57.8 KB Created: 2020-08-27 19:31:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4ef0acf11e5f5f3320c57bb22588c47e SHA-1: bcff1464fb783896e2d713460e36b4d9d68b5e76 SHA-256: 7b58f731d77f231f46cf5b422dc31a905786cd4245c2d5fbf95d8e132abf1d19
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged for containing a malicious redirector link and a large number of external PDF links, suggesting a link farm or spamming operation. The primary malicious URL identified is 'https://ttraff.cc/pify?keyword=story+of+antigone', which is likely used to redirect users to further malicious content. The document body contains garbled text but also includes the primary malicious URL and several other URLs hosted on Shopify and a personal domain, some of which are confirmed benign but others are unknown.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=story+of+antigone
    • http://files.stjameshaubstadt.com/uploads/1/3/0/9/130969003/nirilakid.pdf
    • https://cdn.shopify.com/s/files/1/0432/4599/4146/files/hallie_berry_in_monster_ball.pdf
    • https://cdn.shopify.com/s/files/1/0430/5007/4269/files/kujunakaxu.pdf
    • https://cdn.shopify.com/s/files/1/0437/9105/7058/files/wordly_wise_3000_book_7_lesson_4_answer_key.pdf
    • https://cdn.shopify.com/s/files/1/0431/8153/9483/files/sezuzaberidizuperid.pdf
    • https://cdn.shopify.com/s/files/1/0431/1161/2572/files/igcse_acids_and_bases_notes.pdf
    • https://cdn.shopify.com/s/files/1/0435/3500/7893/files/68582800829.pdf
    • https://cdn.shopify.com/s/files/1/0435/1354/4863/files/74259846917.pdf
    • https://cdn.shopify.com/s/files/1/0441/1988/3928/files/poxifimipovabumax.pdf
    • https://cdn.shopify.com/s/files/1/0429/3551/7337/files/1284434446.pdf
    • https://cdn.shopify.com/s/files/1/0427/7754/2823/files/bumogeledudokufosis.pdf
    • https://cdn.shopify.com/s/files/1/0433/2794/6904/files/boomslang_platform_pedals_weight.pdf
    • https://cdn.shopify.com/s/files/1/0431/2776/7206/files/37488349777.pdf
    • https://cdn.shopify.com/s/files/1/0432/8466/0380/files/57552837807.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006e78.bin
50ce0df02c83eb1d8cf4f7d2338bc4c0324e7bd9bbdc1bb603d69b5115bd980a
pdf-font-stream PDF embedded font (sfnt) at offset 0x6E78 17532 bytes
font_01_sfnt_off0000a62d.bin
5df583e2842056f4bd802c36d444a613b79f09d0520ac3909058b92d64ba70c3
pdf-font-stream PDF embedded font (sfnt) at offset 0xA62D 4928 bytes
font_02_sfnt_off0000b706.bin
0a8d2e8a7b7d0eedfdcf82c64e410aed20c4f6807e1e8f8919fc9c584cc8402a
pdf-font-stream PDF embedded font (sfnt) at offset 0xB706 9904 bytes