Malicious PDF — malware analysis report

Static analysis result for SHA-256 b7778fe377d4a4ab…

MALICIOUS

PDF

47.0 KB Created: 2020-07-30 18:53:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5915a2cea41aea59d338a1e3f7124d1b SHA-1: 06c53c7985c742d20dd4662bd2303f5845667d63 SHA-256: b7778fe377d4a4abe092e40c7d4beb3c79694cddb4fc42dca0c42cf0a25105c2
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.001 User Execution: Malicious Link T1059.001 PowerShell

The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=facts+about+human+brain+pdf'. Additionally, it exhibits a PDF link farm heuristic, indicating a large number of external links, with 'https://cdn.shopify.com/s/files/1/0430/6924/3553/files/82912600122.pdf' being the first listed. These elements suggest the document is designed to redirect users to potentially harmful websites, likely for phishing or malware delivery.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=facts+about+human+brain+pdf
    • http://files.tegnadesigntank.com/uploads/1/3/1/4/131437491/nuvonobudelizowogot.pdf
    • http://files.brickitalia.com/uploads/1/3/1/6/131606822/nobenoju.pdf
    • http://files.snselectricalltd.co.uk/uploads/1/3/1/4/131482916/4c92fcd37b6b0e.pdf
    • http://files.frailtyprevention.co.uk/uploads/1/3/1/4/131437649/fce051e38a8ce.pdf
    • http://files.matharteducation.org/uploads/1/3/0/8/130874400/ef1a27fc26e4.pdf
    • https://cdn.shopify.com/s/files/1/0430/6924/3553/files/82912600122.pdf
    • https://cdn.shopify.com/s/files/1/0434/6845/6102/files/xosinekupopaxasugoza.pdf
    • https://cdn.shopify.com/s/files/1/0434/8762/5369/files/77853586917.pdf
    • https://cdn.shopify.com/s/files/1/0434/7576/3353/files/52310660124.pdf
    • https://cdn.shopify.com/s/files/1/0434/2090/9718/files/zijumowew.pdf
    • https://cdn.shopify.com/s/files/1/0438/2271/0941/files/78010037296.pdf
    • https://cdn.shopify.com/s/files/1/0427/4244/8295/files/wudirolujotamilafesono.pdf
    • https://cdn.shopify.com/s/files/1/0433/0668/0484/files/31058700280.pdf
    • https://cdn.shopify.com/s/files/1/0429/0415/8375/files/dalikixekerosajuz.pdf
    • https://cdn.shopify.com/s/files/1/0433/3341/9160/files/61774511159.pdf
    • https://cdn.shopify.com/s/files/1/0435/3359/8880/files/dofuzip.pdf
    • https://cdn.shopify.com/s/files/1/0427/4431/6070/files/tuwodovalived.pdf
    • https://cdn.shopify.com/s/files/1/0433/9341/7366/files/26237059326.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com/s/files/1/0434/8762/5369/files/77853586917.p

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000079e9.bin
31bf6926aef7c79bcff2891ae7a99f8745f3e341c09542b16ce4bf204ece7f9f
pdf-font-stream PDF embedded font (sfnt) at offset 0x79E9 5224 bytes
font_01_sfnt_off00008b6a.bin
a66a3ebed05bd70c3d7f8498385d65641caf49c1f99de14d35e1ec080527c872
pdf-font-stream PDF embedded font (sfnt) at offset 0x8B6A 10232 bytes