Malicious PDF — malware analysis report

Static analysis result for SHA-256 7becebe1b8ebda66…

MALICIOUS

PDF

68.9 KB Created: 2020-08-08 05:48:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8f2757e5cc0924485207157573dc6268 SHA-1: ec8ea98a249f61cae2c94b0deeed443240c0fe8e SHA-256: 7becebe1b8ebda662b03f938ac8bb5001d8fbe6f05de754b590ab50d9635b29f
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=simple+english+sentences+with+tamil+meaning+pdf'. This indicates the document's primary purpose is to lure the user to a potentially harmful external site. Additionally, the PDF was flagged for containing a mass external PDF link farm, with many links hosted on shopify.com, suggesting an attempt to obscure the malicious redirector or engage in SEO manipulation for distribution. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=simple+english+sentences+with+tamil+meaning+pdf
    • http://dafikad.bhsautomotive.com/uploads/1/3/0/7/130739267/760ee81da.pdf
    • http://files.davidfjasper.com/uploads/1/3/1/6/131607163/5011583.pdf
    • http://files.protoshape.co.uk/uploads/1/3/1/4/131453645/1556887.pdf
    • http://files.craigheadcountyveterans.org/uploads/1/3/1/4/131406715/lilafifazalut.pdf
    • http://files.hannahviera.com/uploads/1/3/2/7/132710697/duriserubiguresaw.pdf
    • https://cdn.shopify.com/s/files/1/0428/4694/5436/files/33153345241.pdf
    • https://cdn.shopify.com/s/files/1/0432/5202/3458/files/57164135250.pdf
    • https://cdn.shopify.com/s/files/1/0434/0160/9366/files/69747244916.pdf
    • https://cdn.shopify.com/s/files/1/0434/7461/6472/files/antimicoticos_2020.pdf
    • https://cdn.shopify.com/s/files/1/0432/1574/9281/files/21496008135.pdf
    • https://cdn.shopify.com/s/files/1/0431/8930/5506/files/analytical_dynamics_baruh.pdf
    • https://cdn.shopify.com/s/files/1/0428/0428/1511/files/zizekagorufimuxijiviza.pdf
    • https://cdn.shopify.com/s/files/1/0428/0126/6851/files/liwiz.pdf
    • https://cdn.shopify.com/s/files/1/0447/1295/1961/files/carabao_grass.pdf
    • https://cdn.shopify.com/s/files/1/0430/2825/0781/files/76757099434.pdf
    • https://cdn.shopify.com/s/files/1/0434/9467/0498/files/91946959755.pdf
    • https://cdn.shopify.com/s/files/1/0434/6055/9013/files/lixikasuradururebew.pdf
    • https://cdn.shopify.com/s/files/1/0434/6380/3046/files/73429915562.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off0000b0d5.bin
fd17805b79abc12d868fc7c73489114d3a9ff6bdf84f23365bf86b87c9bfd38b
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xB0D5 20040 bytes
font_00_sfnt_off00009d96.bin
0e71f27f6874f4cef85492e16eac60297f3d575ca45c99c4dcb2c69d764f0ff5
pdf-font-stream PDF embedded font (sfnt) at offset 0x9D96 5668 bytes
font_02_sfnt_off0000dbde.bin
867546dbeff4fa651468d1d54f5b571fe7b55a64719bbf287cc1aa1398cbe1d9
pdf-font-stream PDF embedded font (sfnt) at offset 0xDBDE 13216 bytes