Malicious PDF — malware analysis report

Static analysis result for SHA-256 3c2be9729117c1de…

MALICIOUS

PDF

73.3 KB Created: 2020-08-15 05:29:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3bdfdc055100022c11e88bcdc0e75b8f SHA-1: 0afc0790d9da53bfbae6f45aa7581c734ef1e3b8 SHA-256: 3c2be9729117c1de0a484bc23533fd9cd74ef7cf63035ba367e1ee664127b6a0
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.001 Malicious Link T1059.001 PowerShell

The PDF file contains a link to a malicious redirector disguised as a parking ticket appeal template. The heuristic PDF_MALICIOUS_REDIRECTOR_LINK confirms the malicious nature of the target URL. Additionally, the PDF_SEO_LINK_FARM heuristic indicates a large number of outbound links, many of which are to benign Shopify URLs, suggesting an attempt to manipulate search results or distribute content. The document body contains urgency language, further supporting a social engineering attack.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=appealing+against+parking+ticket+letter+template
    • http://files.heyletsgetaway.com/uploads/1/3/2/3/132302814/4544922.pdf
    • http://files.k911tacticalcare.com/uploads/1/3/1/3/131378780/1e375.pdf
    • http://files.learn-polish.pl/uploads/1/3/1/4/131453897/nogoli.pdf
    • http://files.rebeccajaynephotography.com/uploads/1/3/0/8/130813934/5078943.pdf
    • https://cdn.shopify.com/s/files/1/0434/2402/2680/files/bomb_calorimeter_download.pdf
    • https://cdn.shopify.com/s/files/1/0429/6641/7567/files/functions_of_management_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0431/5031/1579/files/sat_chemistry_study_guide.pdf
    • https://cdn.shopify.com/s/files/1/0435/2029/5064/files/wiwujamalujejofekozaj.pdf
    • https://cdn.shopify.com/s/files/1/0434/1897/6414/files/safety_harness_parts_name.pdf
    • https://cdn.shopify.com/s/files/1/0437/5016/2583/files/xupusoxoxe.pdf
    • https://cdn.shopify.com/s/files/1/0434/4066/8838/files/13071723179.pdf
    • https://cdn.shopify.com/s/files/1/0430/9227/9460/files/12088304632.pdf
    • https://cdn.shopify.com/s/files/1/0434/1373/3534/files/24471333964.pdf
    • https://cdn.shopify.com/s/files/1/0433/9236/8798/files/14436109302.pdf
    • https://cdn.shopify.com/s/files/1/0428/3065/9750/files/jonijijapubizagolosikonab.pdf
    • https://cdn.shopify.com/s/files/1/0434/8693/7253/files/audience_report_example.pdf
    • https://cdn.shopify.com/s/files/1/0432/2630/0575/files/81171269775.pdf
    • https://cdn.shopify.com/s/files/1/0432/0401/8336/files/32445165532.pdf
    • https://cdn.shopify.com/s/files/1/0432/6106/7428/files/39724169189.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dc50.bin
9eb167df49c16964efeee0778db927c7102758211f02ef63dd0f846854765068
pdf-font-stream PDF embedded font (sfnt) at offset 0xDC50 5304 bytes
font_01_sfnt_off0000ee44.bin
38a5169e5b70298066c09a1d5e28444fd53c3bf0c9c65bdde642c4775cb4244b
pdf-font-stream PDF embedded font (sfnt) at offset 0xEE44 12940 bytes