Malicious PDF — malware analysis report

Static analysis result for SHA-256 c7abb1cbd1e86ce9…

MALICIOUS

PDF

52.3 KB Created: 2020-08-23 07:28:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 46cf9a4bde9205e046364fba236a9094 SHA-1: dad843f4fa52d319ce74c1a0c27bfb41ffb96ed0 SHA-256: c7abb1cbd1e86ce9f7a09821e9c53dcb8668e4a416cf6e6eb8e778a72d87dfad
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, many pointing to Shopify-hosted PDFs, which is indicative of a link farm. One of these links, 'https://ttraff.com/pify?keyword=tutti+insieme+appassionatamente+film+ita', is flagged as a malicious redirector. This suggests the document is designed to lure users to malicious infrastructure, likely for phishing or distributing further malware. No scripts were extracted, and the document body is heavily obfuscated.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=tutti+insieme+appassionatamente+film+ita
    • http://mexobiku.mayflyguides.com/uploads/1/3/1/3/131380550/4c06c70ade.pdf
    • https://cdn.shopify.com/s/files/1/0440/6041/0006/files/62599432531.pdf
    • https://cdn.shopify.com/s/files/1/0430/6688/4250/files/apache_ignite_web_agent.pdf
    • https://cdn.shopify.com/s/files/1/0430/3699/9842/files/77620296151.pdf
    • https://cdn.shopify.com/s/files/1/0433/4570/7166/files/phonetics_transcription_workbook.pdf
    • https://cdn.shopify.com/s/files/1/0449/4236/0744/files/anthropologie_culturelle_cours.pdf
    • https://cdn.shopify.com/s/files/1/0434/4627/2162/files/sakura_ikimono_gakari.pdf
    • https://cdn.shopify.com/s/files/1/0441/0081/2952/files/19068621674.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/64238793182.pdf
    • https://cdn.shopify.com/s/files/1/0429/1746/2182/files/btet_syllabus_2020.pdf
    • https://cdn.shopify.com/s/files/1/0434/8729/7696/files/9493094050.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/1261535930.pdf
    • https://cdn.shopify.com/s/files/1/0434/4469/9288/files/defipotexizolapubaxomujil.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000803b.bin
d091162c66c0fa5125add66d0def19e20c02c1415041a1f25694ad15100d444c
pdf-font-stream PDF embedded font (sfnt) at offset 0x803B 4168 bytes
font_01_sfnt_off00008efe.bin
2361038492c527447a495c7168091c2244de7ba467f1cf2635310e8e33b963c4
pdf-font-stream PDF embedded font (sfnt) at offset 0x8EFE 4900 bytes
font_02_sfnt_off00009f92.bin
36cdd46e0813887bee0cb649595701f01bc9f79cd50b07eb81c50d699a3d3f55
pdf-font-stream PDF embedded font (sfnt) at offset 0x9F92 11108 bytes