Malicious PDF — malware analysis report

Static analysis result for SHA-256 2cf2c6179278c8d6…

MALICIOUS

PDF

41.2 KB Created: 2020-08-30 22:58:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: dac9bc860f758f21cf6786bcd7a900fb SHA-1: 02930d0bc047a9b741da84fd429dc3a267872045 SHA-256: 2cf2c6179278c8d672a54c40a20d6d7e67a220bc013fc4c120fbf96afb1eb232
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic indicating it's a malicious redirector link, pointing to a URL associated with known malicious infrastructure. Additionally, it exhibits characteristics of a link farm, embedding numerous external PDF links, many hosted on Shopify. The document body, though heavily obfuscated, contains text related to 'Society annual return alberta form' and includes the malicious URL, reinforcing the lure. The presence of a fake invoice/payment lure heuristic further supports the phishing pretext.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=society+annual+return+alberta+form
    • https://cdn.shopify.com/s/files/1/0431/5270/3645/files/where_is_utorrent_installed.pdf
    • https://cdn.shopify.com/s/files/1/0440/1309/3029/files/public_private_partnership_models.pdf
    • https://cdn.shopify.com/s/files/1/0432/6473/7448/files/39205078301.pdf
    • https://cdn.shopify.com/s/files/1/0429/4970/5881/files/56083539711.pdf
    • https://cdn.shopify.com/s/files/1/0429/2549/0332/files/86641748766.pdf
    • https://cdn.shopify.com/s/files/1/0435/1895/1576/files/walmart_w2_online.pdf
    • https://cdn.shopify.com/s/files/1/0439/1452/6888/files/52686426424.pdf
    • https://cdn.shopify.com/s/files/1/0430/4479/8613/files/34952979627.pdf
    • https://cdn.shopify.com/s/files/1/0461/9829/2638/files/canon_elph_180_electronic_manual.pdf
    • https://cdn.shopify.com/s/files/1/0428/4484/8295/files/vaxigoniliz.pdf
    • https://cdn.shopify.com/s/files/1/0430/9093/5969/files/42213614574.pdf
    • https://cdn.shopify.com/s/files/1/0430/7386/3842/files/dopoxukixetibiwejefug.pdf
    • https://cdn.shopify.com/s/files/1/0433/4062/8133/files/rameni.pdf
    • https://cdn.shopify.com/s/files/1/0427/8406/3654/files/83152375991.pdf
    • https://cdn.shopify.com/s/files/1/0433/9315/5237/files/18485681562.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000625a.bin
33004920f542af3b5f873dec60557e61861a526addf177a2030819587a95015c
pdf-font-stream PDF embedded font (sfnt) at offset 0x625A 5196 bytes
font_01_sfnt_off000073eb.bin
717e1d9faee7722cfe9e53a7f60df17038e4105076672772aebcbff3e7da13f3
pdf-font-stream PDF embedded font (sfnt) at offset 0x73EB 10616 bytes