Malicious PDF — malware analysis report

Static analysis result for SHA-256 863efc91efbf78c2…

MALICIOUS

PDF

57.3 KB Created: 2020-08-20 11:10:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fdff271fc2ccb6a8350d427512b0a4eb SHA-1: 05ef8faf97771f5a1cf6ac5e2c214168fe18a4ef SHA-256: 863efc91efbf78c28ba1f4a907b8fcd21974d3b8106b136d1cf2a804df697e89
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF file contains numerous embedded links, with one specifically identified as a malicious redirector. The heuristic 'SE_INVOICE_LURE' suggests the document's content is designed to trick the user into clicking the link, likely for phishing or malware delivery. The primary malicious IOC is the redirector URL, which likely leads to further malicious content.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=kanken+laptop+size+guide
    • http://xukimo.wackesfamilyhistory.net/uploads/1/3/2/7/132712593/nirugi-bokepisinimu-fugufomifo.pdf
    • http://wabisiba.ildanceofficials.com/uploads/1/3/1/6/131606289/fejor.pdf
    • https://cdn.shopify.com/s/files/1/0437/3915/2535/files/85347424132.pdf
    • https://cdn.shopify.com/s/files/1/0435/9671/0047/files/aisthesis_jacques_ranciere.pdf
    • https://cdn.shopify.com/s/files/1/0429/5553/8595/files/livro_aromaterapia_gratis.pdf
    • https://cdn.shopify.com/s/files/1/0434/9440/8357/files/22085607973.pdf
    • https://cdn.shopify.com/s/files/1/0427/6482/8838/files/dabuwaxivimoxiru.pdf
    • https://cdn.shopify.com/s/files/1/0431/8976/4245/files/burial_rites_online.pdf
    • https://cdn.shopify.com/s/files/1/0433/8669/9925/files/nubosoxovokujesuzovaxara.pdf
    • https://cdn.shopify.com/s/files/1/0430/4506/0762/files/3025160254.pdf
    • https://cdn.shopify.com/s/files/1/0434/4184/8470/files/cardiac_catheterization_patient_education.pdf
    • https://cdn.shopify.com/s/files/1/0434/5505/3989/files/vakobawajifiduzarerulab.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005eca.bin
103340631dcb9a9cade5ff9a833b5265ba4180d7b4f4d7dd007289b97795d21f
pdf-font-stream PDF embedded font (sfnt) at offset 0x5ECA 21864 bytes
font_01_sfnt_off0000a21e.bin
15d4a61c6c8e825015f41e5c29c7da891236e46bdef26ab86a93ab0f16152f90
pdf-font-stream PDF embedded font (sfnt) at offset 0xA21E 5116 bytes
font_02_sfnt_off0000b39b.bin
7432ecdfba468ebb355410e89b171e74b53f8ce9ff45ae02bc5c559dd9cd4979
pdf-font-stream PDF embedded font (sfnt) at offset 0xB39B 10740 bytes