Malicious PDF — malware analysis report

Static analysis result for SHA-256 9fefb138fc32a1fd…

MALICIOUS

PDF

59.0 KB Created: 2020-07-16 12:41:22 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5ecb34658efc7cb42b94e891b1496bec SHA-1: e5505ea39e5c13c453d5c4b9f7ff15b20d6c2ed8 SHA-256: 9fefb138fc32a1fd9efc453f3cdc47db2e3fc7d4de9405ac786edd7b0a590d02
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.001 Malicious Link T1059.001 PowerShell

The PDF file contains numerous embedded links, with a critical heuristic firing indicating a malicious redirector. The document body, though heavily obfuscated, suggests a lure related to a book title. The primary malicious IOC is the redirector URL, which is likely used to funnel victims to further malicious content. The presence of many external links points to a link farm or SEO poisoning technique.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=os+lusiadas+de+camoes+pdf
    • http://files.hammerwichbowls.com/uploads/1/3/1/3/131383325/26f34a307b13.pdf
    • http://files.oregonfestivalforworldrelief.com/uploads/1/3/1/3/131383673/donokomizun_nexaxo.pdf
    • http://files.pikeboarddd.com/uploads/1/3/0/7/130776518/6154278.pdf
    • http://files.neilbushby.com/uploads/1/3/1/3/131379099/3392620.pdf
    • http://files.storyknowingwithadolescents.net/uploads/1/3/1/0/131070469/5476511.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/rosetotirumeza.pdf
    • https://cdn.shopify.com/s/files/1/0429/4203/8182/files/15992825640.pdf
    • https://cdn.shopify.com/s/files/1/0433/5537/3720/files/lupetolufalaginutisaxo.pdf
    • https://fatoturomixo.files.wordpress.com/2020/06/82700186661.pdf
    • https://faxonitu.files.wordpress.com/2020/06/jetubopitupobuxon.pdf
    • https://gigifovagipe.files.wordpress.com/2020/07/62660207731.pdf
    • https://ligivuv.files.wordpress.com/2020/07/sosapudozavej.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/87074842841.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/xuxovozukirofavekejob.pdf
    • https://cdn.shopify.com/s/files/1/0434/8693/7253/files/mitib.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/pelezegagujagemubejapo.pdf
    • https://cdn.shopify.com/s/files/1/0427/9074/8316/files/17181021178.pdf
    • https://cdn.shopify.com/s/files/1/0431/5794/6530/files/91307503020.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/rixaraxamixenapo.pdf
    • https://cdn.shopify.com/s/files/1/0434/5161/3336/files/tagawixatilanegabug.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a8d9.bin
5140010c33b8c00e8493fdd668a866716893fb57c6daa20d5220c25a673c065f
pdf-font-stream PDF embedded font (sfnt) at offset 0xA8D9 4928 bytes
font_01_sfnt_off0000b9a0.bin
e91f0f466b0fade6abe022772b1166536c2e5c778f3a9b27d164302cc81fb641
pdf-font-stream PDF embedded font (sfnt) at offset 0xB9A0 10720 bytes