Malicious PDF — malware analysis report

Static analysis result for SHA-256 287553d4c2699a8e…

MALICIOUS

PDF

42.4 KB Created: 2020-08-15 05:51:58 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4c81485dab5807f91167a84c18834170 SHA-1: 8f2bc7c325ca8c5a543472a0324aa7c5b177ab29 SHA-256: 287553d4c2699a8eab191e97ddd88161b421b3db6f020b8a438a954d5d940f5d
140 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.001 Malicious Link T1059.001 PowerShell

The PDF contains a large number of embedded links, many of which point to benign Shopify domains, but one critical link redirects through ttraff.cc, a known malicious redirector. The document body, though heavily obfuscated, contains the same malicious URL. This suggests the primary purpose is to redirect users to malicious infrastructure, potentially for phishing or to serve further malware. The presence of a callback lure heuristic further supports a phishing or scam-related intent.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=agadam+bagdam+tigdam+tamil
    • http://files.thehouseofsufyan.com/uploads/1/3/1/4/131407802/6aec00ca67.pdf
    • http://files.misfitspolitics.com/uploads/1/3/2/6/132680784/532634.pdf
    • http://pitelufi.cherylsteventon.co.uk/uploads/1/3/1/3/131384609/1cfe52.pdf
    • http://files.theslaughterhouse1025.com/uploads/1/3/0/9/130969061/92fa1fd74.pdf
    • http://files.nokiddingbaltimore.org/uploads/1/3/1/6/131607103/6605825.pdf
    • https://cdn.shopify.com/s/files/1/0432/2980/6759/files/example_of_job_interview_questions_and_answers.pdf
    • https://cdn.shopify.com/s/files/1/0429/1330/0647/files/26678903523.pdf
    • https://cdn.shopify.com/s/files/1/0429/7487/1711/files/achievers_a1_student_s_book.pdf
    • https://cdn.shopify.com/s/files/1/0438/4007/7986/files/52134417329.pdf
    • https://cdn.shopify.com/s/files/1/0430/1501/2511/files/82463281079.pdf
    • https://cdn.shopify.com/s/files/1/0432/6971/8182/files/historia_del_basquetbol_en_mexico.pdf
    • https://cdn.shopify.com/s/files/1/0431/8950/2110/files/niduworajijifogeni.pdf
    • https://cdn.shopify.com/s/files/1/0432/0460/8155/files/63587281173.pdf
    • https://cdn.shopify.com/s/files/1/0434/2136/8482/files/65835650782.pdf
    • https://cdn.shopify.com/s/files/1/0437/0425/4615/files/anexo_9_oaci.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005a69.bin
953c15122ad326e1e1ae1003f6ec42ce618d0df231fe5fb6d729b59d6b201da7
pdf-font-stream PDF embedded font (sfnt) at offset 0x5A69 4452 bytes
font_01_sfnt_off00006982.bin
d40d9dd688cdf46f37bf287f1e14065a2387523708f25a26c045f5137a677a7f
pdf-font-stream PDF embedded font (sfnt) at offset 0x6982 10860 bytes
font_02_sfnt_off00008e84.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0x8E84 4324 bytes