Malicious PDF — malware analysis report

Static analysis result for SHA-256 860c3eccbc1900f3…

MALICIOUS

PDF

48.0 KB Created: 2020-08-11 06:30:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 114f682a4ecec9dfbf06f462e33715eb SHA-1: 7cbb7dfb6bdccde6121dc193c0ab68afeebb6a8f SHA-256: 860c3eccbc1900f3a4aeb9d0e36db5ea709bed362ec016122a96d9768debfcaf
140 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document impersonates a signing service to trick the user into clicking a link. This link, 'https://ttraff.cc/pify?keyword=small+size+pdf+reader+apk+download', leads to a malicious redirector. The document also contains a large number of links to benign PDFs hosted on Shopify, likely for SEO manipulation to improve the ranking of the malicious link.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Document signing service impersonation lure medium SE_DOCUSIGN_LURE
    Document impersonates DocuSign, Adobe Sign, or a similar signing service in a signing-request context
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=small+size+pdf+reader+apk+download
    • http://vemaxabim.parohia-kassel.de/uploads/1/3/1/4/131438397/kuwimawolusutuv_zenagevok_zubolofujofu.pdf
    • http://files.szynalsessions.com/uploads/1/3/2/7/132740214/dd04431cf.pdf
    • http://files.condoriskadvisors.com/uploads/1/3/0/7/130738928/kagaxewubinos.pdf
    • http://files.richardreedconstruction.com/uploads/1/3/1/3/131397987/084d92c.pdf
    • http://files.doublefarley.com/uploads/1/3/2/6/132683121/ec3149b3ff9.pdf
    • https://cdn.shopify.com/s/files/1/0438/5452/8677/files/anlage_kind_2020_kindergeld.pdf
    • https://cdn.shopify.com/s/files/1/0455/4008/1829/files/mcdonald_s_business_strategy.pdf
    • https://cdn.shopify.com/s/files/1/0437/4482/1399/files/43803908790.pdf
    • https://cdn.shopify.com/s/files/1/0429/4197/2646/files/aisc_steel_construction_manual_15th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0447/6734/6839/files/where_are_my_minecraft_worlds_saved.pdf
    • https://cdn.shopify.com/s/files/1/0428/6752/3743/files/preeclampsia_y_eclampsia_figo.pdf
    • https://cdn.shopify.com/s/files/1/0433/9276/2006/files/wezogewonugijepudapebamog.pdf
    • https://cdn.shopify.com/s/files/1/0433/7188/8803/files/1432245099.pdf
    • https://cdn.shopify.com/s/files/1/0430/2117/2897/files/review_of_medical_microbiology_murray.pdf
    • https://cdn.shopify.com/s/files/1/0431/9127/1586/files/pewudifagewejiz.pdf
    • https://cdn.shopify.com/s/files/1/0435/3579/4327/files/wafarosizuvomelegewupe.pdf
    • https://cdn.shopify.com/s/files/1/0434/3277/1750/files/42015080467.pdf
    • https://cdn.shopify.com/s/files/1/0440/1335/5166/files/apiculture_production_in_ethiopia.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com/s/files/1/0434/3277/1750/files/4201508046

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007084.bin
0aef1530144f26de4a50955b8a60986e4e4551c7187fe930659d1f94dc4f6e55
pdf-font-stream PDF embedded font (sfnt) at offset 0x7084 5496 bytes
font_01_sfnt_off0000832c.bin
ebbcd810f8fa5b483e315d30c78cfaf0e7eb1cd135220752467b762333f37f5e
pdf-font-stream PDF embedded font (sfnt) at offset 0x832C 2692 bytes
font_02_sfnt_off00008ed0.bin
704c3bb77f5f5210d3eeb2d5024aa983303236e5b1973654e13316d1cc596472
pdf-font-stream PDF embedded font (sfnt) at offset 0x8ED0 10420 bytes