Malicious PDF — malware analysis report

Static analysis result for SHA-256 26fd05cc79614dce…

MALICIOUS

PDF

87.9 KB Created: 2020-08-06 17:58:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4f7f90cbbca30d47d570b1632500cdfa SHA-1: 56562df58e05dc1382325cf1acdb0cddb76af179 SHA-256: 26fd05cc79614dce4f62b11e19fbf715dd1329f4e788b446e059a250e74726b6
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=ethical+leadership+journal+pdf'. This indicates the document's primary purpose is to redirect users to malicious infrastructure. The document body, though heavily obfuscated, contains the same URL, reinforcing the malicious intent. The PDF also contains a large number of external links, suggesting a link farm or SEO poisoning tactic to distribute the malicious content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=ethical+leadership+journal+pdf
    • http://walan.birchsage.com/uploads/1/3/1/4/131408027/xafiseji_buvujuluxasuna_watipowawi.pdf
    • http://files.nurianunezhierro.com/uploads/1/3/0/7/130739004/2056361.pdf
    • http://pewego.greenwaynurseryandrainbowclub.com/uploads/1/3/1/1/131163635/2191879.pdf
    • http://files.historichopewellchurch.org/uploads/1/3/1/8/131858791/7265170.pdf
    • http://files.leviathaninc.com/uploads/1/3/1/6/131606262/xupefisesexosu.pdf
    • https://cdn.shopify.com/s/files/1/0429/6785/9359/files/58896745270.pdf
    • https://cdn.shopify.com/s/files/1/0432/6221/4304/files/84601325610.pdf
    • https://cdn.shopify.com/s/files/1/0429/6871/1321/files/diradenegugiwonomapove.pdf
    • https://cdn.shopify.com/s/files/1/0439/0574/5051/files/42031142992.pdf
    • https://cdn.shopify.com/s/files/1/0437/1451/1001/files/recursion_vs_iteration.pdf
    • https://cdn.shopify.com/s/files/1/0439/5663/3758/files/logan_lathe_manual.pdf
    • https://cdn.shopify.com/s/files/1/0434/0324/7781/files/sikeziwuvamiwolal.pdf
    • https://cdn.shopify.com/s/files/1/0429/8126/1466/files/pathfinder_core_rulebook.pdf
    • https://cdn.shopify.com/s/files/1/0440/7181/3285/files/understanding_symbolic_logic_virginia_klenk.pdf
    • https://cdn.shopify.com/s/files/1/0432/3291/9720/files/39803033892.pdf
    • https://cdn.shopify.com/s/files/1/0429/3971/1655/files/xuzedo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000100a1.bin
d778f743969bacaeda726785440cd64f944f7f9457f6a869c743aa9e32c267c2
pdf-font-stream PDF embedded font (sfnt) at offset 0x100A1 5276 bytes
font_01_sfnt_off00011293.bin
3dee8dfd0c11111b39f93238b37ba35a6a45ceb03aa1e2d9edb70c101d5c2161
pdf-font-stream PDF embedded font (sfnt) at offset 0x11293 13112 bytes
font_02_sfnt_off00013d59.bin
275d0ef8f619a30f75d5b67021c85ffe51dbf44d82a44ecb2d07128ff93f9399
pdf-font-stream PDF embedded font (sfnt) at offset 0x13D59 16112 bytes