Malicious PDF — malware analysis report

Static analysis result for SHA-256 c0bc4932ce20ecb4…

MALICIOUS

PDF

35.6 KB Created: 2020-08-01 22:27:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 77df12ed086a4fc44e5eba9cb0651ac8 SHA-1: a52faa75af75fccd2615202aef22025b58ba25fc SHA-256: c0bc4932ce20ecb45d1c82971d407b3db44f8ee5ef950bd2a37f2a3aabd2da35
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=john+deere+185'. Additionally, it exhibits a PDF link farm behavior, embedding numerous external links, many hosted on Shopify. The document body contains the same redirector URL, reinforcing its role in directing users to potentially harmful content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=john+deere+185
    • http://files.doyenskateshop.com/uploads/1/3/2/8/132814427/17fb8c.pdf
    • http://files.solopipingjudges.co.uk/uploads/1/3/0/7/130775971/7342805.pdf
    • http://files.biddislifestyleweddings.com/uploads/1/3/1/4/131407823/688318.pdf
    • https://cdn.shopify.com/s/files/1/0432/9878/3382/files/66029118688.pdf
    • https://cdn.shopify.com/s/files/1/0435/2091/7668/files/kejonojoded.pdf
    • https://cdn.shopify.com/s/files/1/0431/5434/2042/files/how_to_check_nvidia_driver_version.pdf
    • https://cdn.shopify.com/s/files/1/0434/6406/5188/files/99948492144.pdf
    • https://cdn.shopify.com/s/files/1/0427/8134/3903/files/dedinomemexido.pdf
    • https://cdn.shopify.com/s/files/1/0429/9482/7418/files/97171334685.pdf
    • https://cdn.shopify.com/s/files/1/0432/9334/3912/files/jatemolagodagibudogaferi.pdf
    • https://cdn.shopify.com/s/files/1/0436/8341/4169/files/ronufu.pdf
    • https://cdn.shopify.com/s/files/1/0429/9161/6153/files/57468273835.pdf
    • https://cdn.shopify.com/s/files/1/0438/3630/9666/files/ubuntu_flush_dns.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000045ee.bin
d84958f95a106d314e18b9ab0e821683f50e234f81f40c0815363e7d39e1b067
pdf-font-stream PDF embedded font (sfnt) at offset 0x45EE 4852 bytes
font_01_sfnt_off00005672.bin
e901a4728db9831ac588e7cd8e5f004e30be4a77c5fa5b5ab992272b24989758
pdf-font-stream PDF embedded font (sfnt) at offset 0x5672 13756 bytes