Malicious PDF — malware analysis report

Static analysis result for SHA-256 9ef2cc2a3d7a5578…

MALICIOUS

PDF

67.5 KB Created: 2020-07-29 04:01:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7e56be98ed93c0c4f2c8c2e27c01c3a2 SHA-1: 0336639fe49df3917fb1ca793486c1febc5be37c SHA-256: 9ef2cc2a3d7a557898ea4359a8c3cd66a61d38ff89c9a1abd57b98f69c3bc6c3
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a link farm and a specific redirector URL, indicating a lure to external malicious content. The document body, though heavily obfuscated, suggests a 'Bill Gates biography' theme, likely to entice clicks. The presence of numerous PDF links, many pointing to potentially compromised Shopify domains, further supports the attack pattern of using deceptive content to drive traffic to malicious sites.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=bill+gates+biography+book+in+gujarati+pdf
    • http://files.wendycharlton.net/uploads/1/3/1/4/131437987/gatizubosamodefe.pdf
    • http://files.keribaskin.com/uploads/1/3/2/6/132681479/zoradokexorikez.pdf
    • http://files.deniserodgersbooks.com/uploads/1/3/2/3/132303134/vijavamusekaxemomum.pdf
    • http://files.eileenenwrighthodgetts.com/uploads/1/3/1/4/131483445/nevorex.pdf
    • http://files.newellbooks.com/uploads/1/3/0/8/130813797/vapujulo_rajeker_vewidufe.pdf
    • https://cdn.shopify.com/s/files/1/0435/2717/6344/files/73000821768.pdf
    • https://cdn.shopify.com/s/files/1/0430/6763/7922/files/22058295867.pdf
    • https://cdn.shopify.com/s/files/1/0435/5486/5320/files/73445697672.pdf
    • https://cdn.shopify.com/s/files/1/0432/0090/5380/files/96596898762.pdf
    • https://cdn.shopify.com/s/files/1/0431/2177/0656/files/jirofijite.pdf
    • https://cdn.shopify.com/s/files/1/0434/0973/5845/files/fadovisulagumedume.pdf
    • https://cdn.shopify.com/s/files/1/0431/3631/9639/files/laruw.pdf
    • https://cdn.shopify.com/s/files/1/0433/8938/6901/files/fivigavazan.pdf
    • https://cdn.shopify.com/s/files/1/0435/9657/8979/files/21318271501.pdf
    • https://cdn.shopify.com/s/files/1/0432/2131/9839/files/lizukibukozamupewubujukit.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_009_off0000df98.bin
16b410870691a361e0da24932b07c1026fb5f549ffc7fc61345598ae379f88f8
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xDF98 10052 bytes
font_00_sfnt_off00009314.bin
9d21e31263e4296851db688dc8af56d243415b7f4d81b7a35e9875e698705646
pdf-font-stream PDF embedded font (sfnt) at offset 0x9314 5616 bytes
font_01_sfnt_off0000a623.bin
d38b24d963eb8bb984e3e5e6d5d70db7d269bb434fcbf64af87a517dd5e43494
pdf-font-stream PDF embedded font (sfnt) at offset 0xA623 10748 bytes
font_02_sfnt_off0000ca94.bin
43254c6337662e76ed67025008a42d76121bee43b935a85a5f582473253d5118
pdf-font-stream PDF embedded font (sfnt) at offset 0xCA94 16096 bytes