Malicious PDF — malware analysis report

Static analysis result for SHA-256 7df7dbe99bd770c3…

MALICIOUS

PDF

120.3 KB Created: 2020-08-12 14:22:12 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5c102dd0a41d0ee08bf79fb26eeace9c SHA-1: ce9dd4c23f9d467af844178c9fb16212f4b94379 SHA-256: 7df7dbe99bd770c301b2cc03d180bc65b5110cc7ba1cfbf61c6ecf3f729a0beb
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=igcse+biology+notes+pdf+free+download'. Additionally, it exhibits a PDF link farm pattern, with numerous links pointing to external PDFs, including one hosted on 'cdn.shopify.com'. The document body, though heavily obfuscated, contains the same redirect URL, reinforcing the malicious intent. The presence of a visual download button lure further supports the social engineering aspect of this attack.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=igcse+biology+notes+pdf+free+download
    • http://files.younggunsfishingteam.com/uploads/1/3/1/3/131380687/mojixutodod-sobenidurabakiw-pigotemaro-fareririkovokag.pdf
    • http://detonak.missionpossiblefc.com/uploads/1/3/1/3/131398560/topawipumi.pdf
    • http://files.kjamstudios.com/uploads/1/3/0/8/130873943/1da99a173da8.pdf
    • https://cdn.shopify.com/s/files/1/0429/8797/8913/files/nasasa.pdf
    • https://cdn.shopify.com/s/files/1/0432/2784/0669/files/98006799231.pdf
    • https://cdn.shopify.com/s/files/1/0429/3391/1705/files/zonatawelisigodazosebisuf.pdf
    • https://cdn.shopify.com/s/files/1/0431/0158/5569/files/padakejem.pdf
    • https://cdn.shopify.com/s/files/1/0431/7655/8746/files/suzatikeziterisuwejibago.pdf
    • https://cdn.shopify.com/s/files/1/0431/6987/4082/files/grimm_core_rulebook.pdf
    • https://cdn.shopify.com/s/files/1/0429/5042/6780/files/xaxifolapiwowalabugef.pdf
    • https://cdn.shopify.com/s/files/1/0432/1034/2559/files/judopile.pdf
    • https://cdn.shopify.com/s/files/1/0433/6759/6191/files/97160363588.pdf
    • https://cdn.shopify.com/s/files/1/0436/6457/2569/files/organic_chemistry_solomons_12th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0428/9586/8057/files/rotuwaburimawova.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000166c2.bin
85713afcb9091d8b7107c93de814126afb74538d898602e4e41b601c272bbe06
pdf-font-stream PDF embedded font (sfnt) at offset 0x166C2 5596 bytes
font_01_sfnt_off000179dd.bin
edca95673afa34236ee06bd71eac07174e3dccec2f9a0485239d37ed8b23aa3a
pdf-font-stream PDF embedded font (sfnt) at offset 0x179DD 10700 bytes
font_02_sfnt_off00019e9a.bin
7c12020f0b25e69e85aef4ec85e669d6998e273adc80204ab17be37992fd0bdd
pdf-font-stream PDF embedded font (sfnt) at offset 0x19E9A 16096 bytes
font_03_sfnt_off0001b361.bin
805f243b07719f55552fda9d33f04baa7404712def38639d9a36f63ef97b1aeb
pdf-font-stream PDF embedded font (sfnt) at offset 0x1B361 12076 bytes