Malicious PDF — malware analysis report

Static analysis result for SHA-256 fc7b4686eef9ff1f…

MALICIOUS

PDF

44.0 KB Created: 2020-08-26 09:48:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 41b8a01b140f2325fcd5d6c5686c70dc SHA-1: e7aa089c8c597169790e7c66339ca5fb29bfd910 SHA-256: fc7b4686eef9ff1f4e6d3fa3cd6bb7d380bea15cdfe68c82959bb01af7a5dd95
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains multiple embedded links, with one specifically identified as a malicious redirector. The document body, though heavily obfuscated, contains text related to 'drawing book design' and includes the malicious URL. The presence of a 'remote-support tool lure' heuristic suggests an attempt to trick the user into installing potentially unwanted software or granting access. The primary malicious IOC is the redirector URL, which likely leads to further malicious content.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Remote-support tool lure high SE_REMOTE_SUPPORT_LURE
    Document instructs the user to install, open, or connect with a remote-support tool such as AnyDesk, TeamViewer, Quick Assist, or ScreenConnect — high-risk in an unsolicited document
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=drawing+book+design
    • http://xukasa.tmi-photo.com/uploads/1/3/0/8/130814328/9445281.pdf
    • https://cdn.shopify.com/s/files/1/0433/0304/3230/files/94506631641.pdf
    • https://cdn.shopify.com/s/files/1/0439/8976/2206/files/pharmaceutical_calculations_ansel.pdf
    • https://cdn.shopify.com/s/files/1/0444/3108/1639/files/instant_house_mod.pdf
    • https://cdn.shopify.com/s/files/1/0431/0089/7440/files/34302189239.pdf
    • https://cdn.shopify.com/s/files/1/0430/6491/8165/files/69438742649.pdf
    • https://cdn.shopify.com/s/files/1/0436/2852/7779/files/vafalaxozef.pdf
    • https://cdn.shopify.com/s/files/1/0431/6535/2102/files/8488514031.pdf
    • https://cdn.shopify.com/s/files/1/0431/3418/9734/files/67890208242.pdf
    • https://cdn.shopify.com/s/files/1/0432/6057/5912/files/1800223776.pdf
    • https://cdn.shopify.com/s/files/1/0434/6154/2045/files/cpt_2016_professional_edition.pdf
    • https://cdn.shopify.com/s/files/1/0436/9101/6347/files/dufumomipamonadetufixek.pdf
    • https://cdn.shopify.com/s/files/1/0451/7858/5239/files/74870161104.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000061e7.bin
da1e0d08923ce4135c73f7f33ae6a8df5c4dbce911730665cc3cb49522c2d47c
pdf-font-stream PDF embedded font (sfnt) at offset 0x61E7 4964 bytes
font_01_sfnt_off000072d3.bin
8fcaa5b895b3486f5e1554c5b69dd62c89305fae95f254a88ef5857d3e39e138
pdf-font-stream PDF embedded font (sfnt) at offset 0x72D3 10156 bytes
font_02_sfnt_off00009589.bin
7f6049e5011acf0e8581793f2bc2bb947aac2929fdb77abc318b2a6155c1ef71
pdf-font-stream PDF embedded font (sfnt) at offset 0x9589 4324 bytes