Malicious PDF — malware analysis report

Static analysis result for SHA-256 de7f59e7db00ff1f…

MALICIOUS

PDF

52.0 KB Created: 2020-08-03 16:52:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5e26e4849b84964376307d5caba6867b SHA-1: c6393ac550df44107806c44d81fb454d33bf27d2 SHA-256: de7f59e7db00ff1f1223f991c5341148175340af60ae5795f3b2d240271a81cc
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a malicious redirector link pointing to 'https://ttraff.ru/pify?keyword=can+opening+a+pdf+be+dangerous'. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded links, many of which point to benign Shopify domains but are likely used to obscure the malicious redirector. The document body, though heavily obfuscated, contains the malicious URL, suggesting the primary intent is to redirect the user to a potentially harmful site.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=can+opening+a+pdf+be+dangerous
    • http://files.gumshuzchin.com/uploads/1/3/1/4/131407692/9685716.pdf
    • http://files.speedwaysginc.com/uploads/1/3/1/1/131163859/gilirazunibirepono.pdf
    • http://files.thecandyshopprints.com/uploads/1/3/1/0/131070918/xemusetesemet.pdf
    • https://cdn.shopify.com/s/files/1/0439/0735/0696/files/baofeng_bf-_888s_frequencies.pdf
    • https://cdn.shopify.com/s/files/1/0428/8456/3110/files/hamilton_beach_microwave_parts.pdf
    • https://cdn.shopify.com/s/files/1/0432/4478/1735/files/61416950001.pdf
    • https://cdn.shopify.com/s/files/1/0429/7365/9290/files/44081626812.pdf
    • https://cdn.shopify.com/s/files/1/0431/4133/3147/files/rerapufurunev.pdf
    • https://cdn.shopify.com/s/files/1/0432/4327/4395/files/zijevotogobalijet.pdf
    • https://cdn.shopify.com/s/files/1/0431/1092/4437/files/abbreviation_for_philippians.pdf
    • https://cdn.shopify.com/s/files/1/0431/7885/2507/files/mabepozifopug.pdf
    • https://cdn.shopify.com/s/files/1/0434/0334/6078/files/jitexenitiga.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/kepudanunakadop.pdf
    • https://cdn.shopify.com/s/files/1/0430/8064/6807/files/79363179671.pdf
    • https://cdn.shopify.com/s/files/1/0432/9357/3284/files/bimixofiwogimazoge.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/satofekefekuwozavobijogut.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008e06.bin
e0ea8b060316503129be46a96a0055afc634ba265fde86554db5fd00ee42297c
pdf-font-stream PDF embedded font (sfnt) at offset 0x8E06 5220 bytes
font_01_sfnt_off00009fd0.bin
778611b14fd55eae982b5450f553e3b839ebfacca732fdc4393f8cce2c118f1c
pdf-font-stream PDF embedded font (sfnt) at offset 0x9FD0 10248 bytes