Malicious PDF — malware analysis report

Static analysis result for SHA-256 f7ec980f59381f0e…

MALICIOUS

PDF

59.0 KB Created: 2020-08-14 04:46:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d5184b7f20c7442fcbf814504db30b27 SHA-1: a0fbde4e51733c4a0393b8fe4a8864f98a38faf8 SHA-256: f7ec980f59381f0e2b2ae4c272a6b7b5e1086f55730c57c2f1aa5bd8e47e381f
140 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link to a known malicious redirector, ttraff.cc, which is part of a link farm designed to attract search engine traffic. The document body, though heavily obfuscated, contains the URL that is also present in the heuristics. This suggests the document's primary purpose is to redirect users to malicious content, likely for phishing or malware distribution.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • QR-code redirect lure medium SE_QR_LURE
    Document instructs the user to scan a QR code with a phone — consistent with QR phishing, but also common in legitimate documents
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=dreamweaver+cs3+full+tutorial+pdf
    • http://files.skanlabnorge.com/uploads/1/3/2/6/132681619/7894144.pdf
    • http://files.ledtolead.org/uploads/1/3/2/7/132710678/f2c3ac13a8e.pdf
    • http://gurale.knarlyknot.com/uploads/1/3/0/7/130740522/zijuxebowuxepij_godeb.pdf
    • https://cdn.shopify.com/s/files/1/0439/8101/3150/files/pepurujog.pdf
    • https://cdn.shopify.com/s/files/1/0432/9832/4638/files/sapisamukuwavozokelob.pdf
    • https://cdn.shopify.com/s/files/1/0441/0851/3432/files/libros_de_autores_argentinos_en.pdf
    • https://cdn.shopify.com/s/files/1/0433/0350/1989/files/clinical_pharmacist_job_description.pdf
    • https://cdn.shopify.com/s/files/1/0430/0718/0954/files/cycling_time_trial_training_plan.pdf
    • https://cdn.shopify.com/s/files/1/0437/9394/0629/files/cadena_de_suministro_ejemplo.pdf
    • https://cdn.shopify.com/s/files/1/0428/9937/4233/files/68543991816.pdf
    • https://cdn.shopify.com/s/files/1/0431/4916/4698/files/tibirorirane.pdf
    • https://cdn.shopify.com/s/files/1/0431/4189/0210/files/39378393839.pdf
    • https://cdn.shopify.com/s/files/1/0434/0557/4309/files/33341342704.pdf
    • https://cdn.shopify.com/s/files/1/0436/0595/0626/files/zefinuvema.pdf
    • https://cdn.shopify.com/s/files/1/0439/5896/0286/files/liste_adjectif_anglais_ordre_alphabetique.pdf
    • https://cdn.shopify.com/s/files/1/0437/7152/7325/files/analisis_toxicologico_de_cannabinoides_en_orina.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009ad5.bin
722df6df1fc0a5be693ad3dbc154f4a9b489111f9c135984cfdbce2f47925053
pdf-font-stream PDF embedded font (sfnt) at offset 0x9AD5 5616 bytes
font_01_sfnt_off0000aded.bin
4107bd9b3a4fae4caf1556fd95b3826cbd67d1594425aefaa55e6a63be0a8f2c
pdf-font-stream PDF embedded font (sfnt) at offset 0xADED 15440 bytes