Malicious PDF — malware analysis report

Static analysis result for SHA-256 bc6dbda88298fe26…

MALICIOUS

PDF

41.7 KB Created: 2020-08-08 18:43:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6d22947269de687b2aafd2ca105b70b3 SHA-1: 5c7e47bbd8fcb6bf889a1753f02ac77a40ee6b16 SHA-256: bc6dbda88298fe267790aa59b0e8c719435ec471a73a2f12b9b3e3b36ad9722e
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.ru/pify?keyword=broiler+and+layer+management+pdf'. It also exhibits characteristics of a PDF link farm, with numerous external links, including one to 'https://cdn.shopify.com/s/files/1/0430/1537/2953/files/31808232750.pdf'. The document body, though heavily obfuscated, contains text related to broiler and layer management, suggesting a lure to disguise the malicious intent.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=broiler+and+layer+management+pdf
    • http://files.delinadream.com/uploads/1/3/1/6/131606694/mulugumopa-banime-viduzig-runadi.pdf
    • http://files.equi-line.net/uploads/1/3/1/3/131379343/muramoravajusad-ketixuvodoteja.pdf
    • http://zixusimi.ecogreenairsolutions.com/uploads/1/3/2/6/132682883/0602c31b31c6.pdf
    • http://files.blacksheepswimwear.com/uploads/1/3/2/3/132303019/02e3101d1b.pdf
    • http://files.marinamontes.com/uploads/1/3/1/4/131438819/pixumokubekiru.pdf
    • http://files.blacksheepswimwear.com/uploads/1/3/2/3/132303019/02e31
    • https://cdn.shopify.com/s/files/1/0430/1537/2953/files/31808232750.pdf
    • https://cdn.shopify.com/s/files/1/0437/0595/8565/files/tratamiento_adenitis_mesenterica_en_nios.pdf
    • https://cdn.shopify.com/s/files/1/0437/7106/8577/files/sear_kenmore_sewing_machine_manual.pdf
    • https://cdn.shopify.com/s/files/1/0429/5986/3961/files/28229767844.pdf
    • https://cdn.shopify.com/s/files/1/0431/2170/5124/files/panefunudi.pdf
    • https://cdn.shopify.com/s/files/1/0431/4962/3462/files/developing_effective_assessment_in_higher_education.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/84712881745.pdf
    • https://cdn.shopify.com/s/files/1/0429/7634/6266/files/keurig_k60_manual.pdf
    • https://cdn.shopify.com/s/files/1/0433/8168/6439/files/jajenitive.pdf
    • https://cdn.shopify.com/s/files/1/0432/4907/4336/files/50046927787.pdf
    • https://cdn.shopify.com/s/files/1/0428/5143/4659/files/66693744998.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006529.bin
211416b4a5328d376b462ae417c42abbbcb2700b7dc2d1f1341b729dbae9921e
pdf-font-stream PDF embedded font (sfnt) at offset 0x6529 5332 bytes
font_01_sfnt_off00007748.bin
8a7fb7ad0296d65241e7c065622dd9f6c64dba71de3cb5d19f2a056406dde944
pdf-font-stream PDF embedded font (sfnt) at offset 0x7748 10084 bytes