Malicious PDF — malware analysis report

Static analysis result for SHA-256 9991f17aa224f4b8…

MALICIOUS

PDF

41.0 KB Created: 2020-08-04 03:24:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 607235677bbcff71912cf3f56cce1153 SHA-1: e542cf4fc3933be3a87670caa81419c925e6b6f0 SHA-256: 9991f17aa224f4b8da214ce51c3dc96393f22087e0074157119b587b2c40c011
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://ttraff.com/pify?keyword=acetilcolina+farmacocinetica+pdf'. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded URLs, many hosted on cdn.shopify.com. The document body, though heavily obfuscated, contains the same malicious URL. The primary attack pattern involves luring the user to click the malicious link, likely leading to a phishing or scam page.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=acetilcolina+farmacocinetica+pdf
    • http://files.noondayfarm.org/uploads/1/3/1/6/131637055/f759d94cdcb.pdf
    • http://files.antoniocoach.com/uploads/1/3/2/6/132681316/85b91a4acc4b7c3.pdf
    • http://files.bioprimehp.ca/uploads/1/3/0/8/130874254/6914273.pdf
    • http://files.byhisgracehymns.com/uploads/1/3/1/4/131453188/3017069.pdf
    • https://cdn.shopify.com/s/files/1/0428/4838/7239/files/68458852402.pdf
    • https://cdn.shopify.com/s/files/1/0432/2358/0830/files/wawurumevebetozipus.pdf
    • https://cdn.shopify.com/s/files/1/0433/0897/4235/files/51338295727.pdf
    • https://cdn.shopify.com/s/files/1/0437/6290/9335/files/adrenalectomia_laparoscopica.pdf
    • https://cdn.shopify.com/s/files/1/0429/6943/2230/files/php_get_first_element_of_array.pdf
    • https://cdn.shopify.com/s/files/1/0432/2453/1101/files/51968806580.pdf
    • https://cdn.shopify.com/s/files/1/0430/1442/2677/files/vaviwaroxopisasopodejix.pdf
    • https://cdn.shopify.com/s/files/1/0434/7258/4870/files/70476076419.pdf
    • https://cdn.shopify.com/s/files/1/0434/7537/0136/files/zerevivaropezigawebatejij.pdf
    • https://cdn.shopify.com/s/files/1/0431/4228/3432/files/lezevobuxofipi.pdf
    • https://cdn.shopify.com/s/files/1/0433/8706/0378/files/zewele.pdf
    • https://cdn.shopify.com/s/files/1/0431/3251/8555/files/vesojut.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006382.bin
46f1b9693f8d15785701158c28a347be0dbd6a8902d5c5fa8a64e3db8f87a296
pdf-font-stream PDF embedded font (sfnt) at offset 0x6382 5112 bytes
font_01_sfnt_off000074d4.bin
6a5a21967462d2208bfcc0e3c0b39b686f042287095adeb8f8cfe0dd36b97afa
pdf-font-stream PDF embedded font (sfnt) at offset 0x74D4 9964 bytes