Malicious PDF — malware analysis report

Static analysis result for SHA-256 1efd63c451948c41…

MALICIOUS

PDF

52.3 KB Created: 2020-08-23 17:42:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3cfdfc625cabb62643df2b1a0d5cc24f SHA-1: 86e84bbb1c5de74635a2adfb52b4d448dcb9eec9 SHA-256: 1efd63c451948c410504382089e6f13d84a4f73bd1d17088c4df6ee42b21c244
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a link farm and a critical heuristic firing for a malicious redirector. The embedded URL, https://ttraff.com/pify?keyword=bts+love+yourself+answer+photoshoot+s+version, is likely intended to lure users into clicking on it, potentially leading to further malicious content or downloads. The document body, though heavily obfuscated, contains references to this URL and other Shopify links, suggesting a social engineering attempt.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=bts+love+yourself+answer+photoshoot+s+version
    • http://files.idyllicliving.com/uploads/1/3/0/8/130873855/mexurarogosu.pdf
    • http://files.richardellishair.co.uk/uploads/1/3/0/9/130969061/d909b6165a5.pdf
    • http://files.just4youtreats.com/uploads/1/3/1/4/131406893/gukazives.pdf
    • http://files.spiritualfringe.com/uploads/1/3/0/7/130775866/xawewiwibew.pdf
    • https://cdn.shopify.com/s/files/1/0427/4143/2487/files/rengar_build_s7.pdf
    • https://cdn.shopify.com/s/files/1/0431/9304/1053/files/98004491496.pdf
    • https://cdn.shopify.com/s/files/1/0439/4693/4430/files/42540197184.pdf
    • https://cdn.shopify.com/s/files/1/0439/3422/0456/files/3206983309.pdf
    • https://cdn.shopify.com/s/files/1/0431/0741/8273/files/livro_de_agrometeorologia.pdf
    • https://cdn.shopify.com/s/files/1/0436/5352/9753/files/lupevejekerobu.pdf
    • https://cdn.shopify.com/s/files/1/0441/2784/6552/files/67966518523.pdf
    • https://cdn.shopify.com/s/files/1/0439/3756/2779/files/cambridge_igcse_business_studies_fourth_edition.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000051e4.bin
1ad172f25a16fbc70e75665a74f71253dd714e9273c4b776a377ea9718b32e8a
pdf-font-stream PDF embedded font (sfnt) at offset 0x51E4 4096 bytes
font_01_sfnt_off0000606e.bin
2ef301e7946874ad3fb23fa36367fd09b8563f6b5fb8a9b7091ac5e130cdf4a6
pdf-font-stream PDF embedded font (sfnt) at offset 0x606E 5292 bytes
font_02_sfnt_off0000727f.bin
b510c529800d5d440e7be8423cfc673bc2d8ccc75e8eef988a02e6f344cfbe40
pdf-font-stream PDF embedded font (sfnt) at offset 0x727F 1984 bytes
font_03_sfnt_off00007bf1.bin
4f601cee73a4b9ab0b8169048c11c28a8bb0eb63ab0ca06d376e425b8f0ef9ec
pdf-font-stream PDF embedded font (sfnt) at offset 0x7BF1 10368 bytes
font_04_sfnt_off00009fa4.bin
b482232ef79762c691d84f71f59dcededbfa18f69e90926be576c77f0ee50992
pdf-font-stream PDF embedded font (sfnt) at offset 0x9FA4 16852 bytes
font_05_sfnt_off0000b7d4.bin
e2f50d5f4e3fc2e46405e9f934f61f85e6ad4dd4f1a71686478313b05a5ff7cb
pdf-font-stream PDF embedded font (sfnt) at offset 0xB7D4 1932 bytes