Malicious PDF — malware analysis report

Static analysis result for SHA-256 cfcfbfdd666d3a07…

MALICIOUS

PDF

47.9 KB Created: 2020-08-04 13:01:59 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 86706941b16a2d0a05a51966bb045da5 SHA-1: 339534c86d2ab3d3b4551cf8ecefca43e5d15c28 SHA-256: cfcfbfdd666d3a073542c00d655d5eca3aedcbdd85d0db0f486c55b080ba506c
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains numerous embedded links, with one identified as a malicious redirector. The heuristic 'PDF_MALICIOUS_REDIRECTOR_LINK' indicates that the link `https://ttraff.cc/pify?keyword=factors+affecting+acoustics+of+buildings+pdf` leads to known malicious infrastructure. The 'PDF_SEO_LINK_FARM' heuristic further suggests a pattern of hosting many external PDF links, likely to manipulate search engine results or distribute malicious content. The document body, though partially corrupted, contains text related to the topic of building acoustics and the malicious URL, reinforcing the lure.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=factors+affecting+acoustics+of+buildings+pdf
    • http://files.boaznoy.com/uploads/1/3/0/7/130740493/subakum.pdf
    • http://files.pasturedpoultryinfo.com/uploads/1/3/1/3/131383541/selogofu.pdf
    • http://files.cetonantzin.org/uploads/1/3/2/6/132696122/d006b.pdf
    • http://files.waynecdmi.org/uploads/1/3/0/9/130969489/gibewitezi_zilugewopojat.pdf
    • https://cdn.shopify.com/s/files/1/0431/0292/9047/files/mulelonoliza.pdf
    • https://cdn.shopify.com/s/files/1/0433/7877/0076/files/lexosifefuxetarenikam.pdf
    • https://cdn.shopify.com/s/files/1/0435/3913/6661/files/sebotoratomu.pdf
    • https://cdn.shopify.com/s/files/1/0429/7624/7967/files/44823282605.pdf
    • https://cdn.shopify.com/s/files/1/0433/3935/0181/files/lufujelujibegorojemok.pdf
    • https://cdn.shopify.com/s/files/1/0432/4176/7072/files/31481366376.pdf
    • https://cdn.shopify.com/s/files/1/0431/1059/6765/files/yardi_training_manual.pdf
    • https://cdn.shopify.com/s/files/1/0430/6462/3265/files/65947044936.pdf
    • https://cdn.shopify.com/s/files/1/0431/7508/4193/files/jubumapimikizujefur.pdf
    • https://cdn.shopify.com/s/files/1/0431/3242/0262/files/71794170683.pdf
    • https://cdn.shopify.com/s/files/1/0430/7465/0261/files/gojunerifovepukiradun.pdf
    • https://cdn.shopify.com/s/files/1/0437/7303/4654/files/12725025382.pdf
    • https://cdn.shopify.com/s/files/1/0431/5329/3469/files/nivimurubewib.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000740c.bin
dc126971425dcf12fa012b8fb80f55b60e816242090550cdd91874a8320b6008
pdf-font-stream PDF embedded font (sfnt) at offset 0x740C 5420 bytes
font_01_sfnt_off00008680.bin
a042371e70daefdcaaf68506e1334359214bc01e1a4d7e42654248aa9e042612
pdf-font-stream PDF embedded font (sfnt) at offset 0x8680 13704 bytes