Malicious PDF — malware analysis report

Static analysis result for SHA-256 9c3b3eb6dfd84711…

MALICIOUS

PDF

44.1 KB Created: 2020-08-08 18:31:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6d59dea6ce0d88b53e0b19bd14b640a3 SHA-1: ceb5a5167147301bfb90fa76793b0731ff1945c9 SHA-256: 9c3b3eb6dfd84711a70a424198a7cdb4b6199b3d4c8a432ee6a50aa4c82b4539
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=horrible+histories+frightful+first+world+war+pdf'. This indicates a social engineering lure, likely attempting to trick the user into downloading further malware or visiting a malicious site. The document also contains a large number of external links, many hosted on Shopify, which is characteristic of SEO link farm abuse to improve search engine ranking for malicious content. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=horrible+histories+frightful+first+world+war+pdf
    • http://files.hfndpa.com/uploads/1/3/1/4/131437312/297962c4134c.pdf
    • http://files.cjbands.org/uploads/1/3/1/4/131453230/349e52f602e.pdf
    • http://files.4hcampohio.org/uploads/1/3/1/4/131453208/fifaxedilebabix_nigute_jumod_rapekarugiki.pdf
    • http://files.thecookingkettle.com/uploads/1/3/1/6/131606331/fb58ce7.pdf
    • http://files.lironstravelblog.com/uploads/1/3/1/0/131070459/buwudejumide-mawedababibu-zegudotiboba-jekaloniko.pdf
    • https://cdn.shopify.com/s/files/1/0431/7744/3483/files/92251038690.pdf
    • https://cdn.shopify.com/s/files/1/0431/5725/8402/files/dunisim.pdf
    • https://cdn.shopify.com/s/files/1/0429/4855/9004/files/tufobeju.pdf
    • https://cdn.shopify.com/s/files/1/0435/1646/1211/files/lajobitiretutexonu.pdf
    • https://cdn.shopify.com/s/files/1/0438/2710/1853/files/lafetivawituruvitari.pdf
    • https://cdn.shopify.com/s/files/1/0434/2421/9288/files/78199282874.pdf
    • https://cdn.shopify.com/s/files/1/0435/5876/4696/files/bopilesumiwiko.pdf
    • https://cdn.shopify.com/s/files/1/0428/9141/1615/files/memorandum_for_record_army_example_wlc.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/beloromawodosuxaso.pdf
    • https://cdn.shopify.com/s/files/1/0433/7179/0486/files/tamifupipulazojexum.pdf
    • https://cdn.shopify.com/s/files/1/0432/5569/3470/files/lakedalef.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000643c.bin
bf645e2b21195aab4da3fff7f7465d8cf35f7cd70ccf7a833e7a64f9b93cb4b0
pdf-font-stream PDF embedded font (sfnt) at offset 0x643C 5496 bytes
font_01_sfnt_off000076ef.bin
60da281517c7cb78bef459db1e7956a63f87324a277e95b0613be82befa00733
pdf-font-stream PDF embedded font (sfnt) at offset 0x76EF 13944 bytes