Malicious PDF — malware analysis report

Static analysis result for SHA-256 f7dc2fb756ab2691…

MALICIOUS

PDF

298.1 KB Created: 2020-09-09 12:55:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7decc8325e173ff17e334a8659b6154d SHA-1: faacac28a11fd6962d9942c287d833fd543939a1 SHA-256: f7dc2fb756ab2691da7473f1f05c6c112e195be0c6fdc5bfec121dd3726e7a06
68 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.001 Malicious Link T1059.001 PowerShell

The PDF contains a link that redirects to malicious infrastructure, as indicated by the PDF_MALICIOUS_REDIRECTOR_LINK heuristic. The document body, though heavily obfuscated, contains the text 'Beautiful creatures book free' and the malicious URL, suggesting a lure to download content. The SE_URGENCY_LURE heuristic also suggests a social engineering tactic was employed.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/pify?keyword=beautiful+creatures+book+free
    • https://cdn.shopify.com/s/files/1/0435/9569/4239/files/wetolaw.pdf
    • https://cdn.shopify.com/s/files/1/0462/7156/1890/files/galovi.pdf
    • https://cdn.shopify.com/s/files/1/0428/9291/8937/files/werijogimopa.pdf
    • https://cdn.shopify.com/s/files/1/0432/8862/5302/files/49793981619.pdf
    • https://cdn.shopify.com/s/files/1/0433/2558/7610/files/20920887012.pdf
    • https://static.usrfiles.com/ugd/8ac1ab_37a81db9eba74ee3bc12b7cbc0b284bf.pdf
    • https://static.usrfiles.com/ugd/3c9ac1_7c6b2171b0624368849385c63997fb7b.pdf
    • https://static.usrfiles.com/ugd/1a94e8_095d5bfe9daf48358cf97f57441cd35b.pdf
    • https://static.usrfiles.com/ugd/808d8c_8f5a6e3d092b4cc483494e6731170293.pdf
    • https://static.usrfiles.com/ugd/409ca8_e2b2c9b8ec00464e82f26eba90d2c5d4.pdf
    • https://static.usrfiles.com/ugd/837d34_e2760b83e5e24824b8cd6f50ed0a5d74.pdf
    • https://static.usrfiles.com/ugd/10b11f_635ad54718794f75835cb7d001bcfbeb.pdf
    • https://static.usrfiles.com/ugd/ee6100_a827305a88ee4b59a6a84b930364c5b2.pdf
    • https://static.usrfiles.com/ugd/1f2646_8e8a8679598442a188a5c6b513501e4d.pdf
    • https://static.usrfiles.com/ugd/69a512_bc26c267c7594a6795d4d348613e434b.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00046093.bin
63d53b581e769ccc360680278bc0604b131d23a2df92b9d6c78db85c4092d28b
pdf-font-stream PDF embedded font (sfnt) at offset 0x46093 5128 bytes
font_01_sfnt_off00047219.bin
6fb819c81057f5a684fe4026264951b4aecdd8d139c1321d007489362ea409b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x47219 12236 bytes