Malicious PDF — malware analysis report

Static analysis result for SHA-256 b1a858d6278f9a77…

MALICIOUS

PDF

68.8 KB Created: 2020-08-23 05:17:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7df0d5af2bdb7831390020f35799794e SHA-1: bb37acbae0871e7e866dbea51dfad62cd4472d98 SHA-256: b1a858d6278f9a777b9de2bf739e5d01bc3e1e1799ca3af87280b3e2bdee3a7e
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was identified as malicious due to its structure containing a large number of external links, a technique often used in SEO link farms to manipulate search rankings or distribute malicious content. One critical heuristic specifically flagged it as a 'PDF_MALICIOUS_REDIRECTOR_LINK', pointing to 'https://ttraff.cc/pify?keyword=campaign+meaning+pdf', which is a known malicious redirector. The document body, though heavily obfuscated, also contains this URL, reinforcing the malicious intent. The file's purpose appears to be to lure users into clicking these links, which likely lead to further malicious sites.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=campaign+meaning+pdf
    • http://files.intentionalenrichment.com/uploads/1/3/0/8/130814874/mipavuw_pejiripomosuf_zowivixux.pdf
    • https://cdn.shopify.com/s/files/1/0429/7916/4314/files/25743046417.pdf
    • https://cdn.shopify.com/s/files/1/0435/6141/8913/files/behavioural_ecology_an_evolutionary_approach.pdf
    • https://cdn.shopify.com/s/files/1/0427/6961/2966/files/nirugolusi.pdf
    • https://cdn.shopify.com/s/files/1/0427/7898/4614/files/56870817777.pdf
    • https://cdn.shopify.com/s/files/1/0431/9268/0605/files/48103224087.pdf
    • https://cdn.shopify.com/s/files/1/0435/5581/5583/files/bahadur_shah_1_information.pdf
    • https://cdn.shopify.com/s/files/1/0433/3905/5258/files/tosidepudi.pdf
    • https://cdn.shopify.com/s/files/1/0429/5032/8486/files/20787464793.pdf
    • https://cdn.shopify.com/s/files/1/0440/2796/9686/files/kiwinikimapoxuzu.pdf
    • https://cdn.shopify.com/s/files/1/0428/1715/9335/files/bio_free.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000061df.bin
dbb4a8b0e7af5cf8272bbaad3aadea34878c9ce453d164dd72f74cde3cc7a4ac
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x61DF 13252 bytes
font_01_sfnt_off00008ccc.bin
db5f8c8fca0c14d5a6c04a7a6209cf89f18a33ebd9e8235eff6047926488d850
pdf-font-stream PDF embedded font (sfnt) at offset 0x8CCC 4676 bytes
font_02_sfnt_off00009c8e.bin
a8cb3a8f890e97dc79c9534bb540e98a1da1f0f3c57b17bf54bed01d4c149056
pdf-font-stream PDF embedded font (sfnt) at offset 0x9C8E 9796 bytes
font_03_sfnt_off0000b7fe.bin
fbb54c0a56bdf820a07a6e1b1541f1d59f023126ca5e1560e9821eccf4aab9d3
pdf-font-stream PDF embedded font (sfnt) at offset 0xB7FE 10844 bytes
font_04_sfnt_off0000dd3b.bin
17855735673a29c88710480ecd39a453f25f4ee877539cd13855857389c32955
pdf-font-stream PDF embedded font (sfnt) at offset 0xDD3B 17476 bytes
font_05_sfnt_off0000f758.bin
a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f
pdf-font-stream PDF embedded font (sfnt) at offset 0xF758 4324 bytes