Malicious PDF — malware analysis report

Static analysis result for SHA-256 bf073aca354f49af…

MALICIOUS

PDF

44.9 KB Created: 2020-08-26 01:20:59 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ffbecceb8937d04d9cc37f5fbd357353 SHA-1: d00f7ac99e00c0f3da64bfa146e78f04a3f9000d SHA-256: bf073aca354f49afbf4621ce51f9ccf27dee572afdd7602c090488a1a12c523e
220 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains multiple heuristics indicating malicious intent, including direct payload links and malicious redirectors. The primary malicious URL identified is https://ttraff.cc/pify?keyword=sex+viet+nam+.com, which is likely used to redirect users to a harmful site. The document also contains a large number of links to external PDFs, some of which are hosted on Shopify, potentially for SEO manipulation or to mask malicious activity. The presence of parser-evasion techniques further supports the malicious classification.

Heuristics 5

  • PDF link points directly to executable/archive payload critical PDF_DIRECT_PAYLOAD_LINK
    PDF contains a clickable HTTP(S) URI whose path ends in an executable, script, shortcut, disk image, or archive extension. Documents can legitimately link to installers, so this is a high-risk delivery indicator rather than a standalone exploit fingerprint.
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Clickable PDF combines external action with parser-evasion structure high PDF_ACTION_PARSER_EVASION
    PDF has an external clickable URI together with object graph or xref structures that make parsers disagree, such as divergent duplicate objects, parser divergence, or xref offset mismatch. That combination is stronger than a plain link: the document is both an outward-action carrier and a parser-confusion/evasion sample.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=sex+viet+nam+.com
    • http://wovutuza.johnpconoverphotography.com/uploads/1/3/0/7/130739704/2a056d070b4d.pdf
    • http://files.tcquality.com/uploads/1/3/1/3/131379939/8618551.pdf
    • http://nuwabu.bombersouth.com/uploads/1/3/0/7/130740008/woburis-pujuzidabu-wozaduduxu.pdf
    • http://files.mayolivestock.com/uploads/1/3/2/7/132740951/6463204.pdf
    • http://taras.wctherapygroup.com/uploads/1/3/2/6/132696056/tijozotolamawot-raniveruv-rupefewi.pdf
    • https://cdn.shopify.com/s/files/1/0461/2154/9988/files/7._2_identifying_energy_transformations_worksheet_answers.pdf
    • https://cdn.shopify.com/s/files/1/0429/0704/1958/files/reduced_hybrid_viability.pdf
    • https://cdn.shopify.com/s/files/1/0432/6418/0390/files/elizabeth_bathory_biography.pdf
    • https://cdn.shopify.com/s/files/1/0433/2827/4585/files/44221873981.pdf
    • https://cdn.shopify.com/s/files/1/0437/1107/0357/files/4265656013.pdf
    • https://cdn.shopify.com/s/files/1/0428/9911/2095/files/sheekkoo_afaan_oromoo.pdf
    • https://cdn.shopify.com/s/files/1/0429/9581/0455/files/zaxukedimifi.pdf
    • https://cdn.shopify.com/s/files/1/0431/0971/2021/files/jubizemebimat.pdf
    • https://cdn.shopify.com/s/files/1/0431/1092/4437/files/abbreviation_for_philippians.pdf
    • https://cdn.shopify.com/s/files/1/0434/4066/8838/files/cubase_6_torrents.pdf
    • https://cdn.shopify.com/s/files/1/0437/5294/7863/files/degomajatizu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005a9d.bin
fbfc2ad5cbe3701cd84329435856f3a72ff04652a5bd0a509ad6f52a726b08db
pdf-font-stream PDF embedded font (sfnt) at offset 0x5A9D 3324 bytes
font_01_sfnt_off00006696.bin
2df7f4e94fab952f57b7e3b502aeccfd0b80430789ddbf434f36f0b51033b72a
pdf-font-stream PDF embedded font (sfnt) at offset 0x6696 4692 bytes
font_02_sfnt_off0000766e.bin
fd62c6e710567c0eda69819ccb73a8c08c08c2974ef6bba3d3df2941abb42acd
pdf-font-stream PDF embedded font (sfnt) at offset 0x766E 9904 bytes
font_03_sfnt_off0000984b.bin
1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361
pdf-font-stream PDF embedded font (sfnt) at offset 0x984B 4324 bytes