Malicious PDF — malware analysis report

Static analysis result for SHA-256 48ed26c57f8faaad…

MALICIOUS

PDF

51.0 KB Created: 2020-08-05 00:29:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9122b1558d8963a8eff98bae74b3a22c SHA-1: e6045ab74577e7b241572d4b5678f5289d719bd7 SHA-256: 48ed26c57f8faaad4acc18506c3666f96c64a4b623406e65d15a3560157084bd
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a critical heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.cc/pify?keyword=architecture+portfolio+samples+pdf'. This URL is presented within the document body, disguised as a benign link. The file also exhibits a PDF SEO link farm heuristic, indicating a large number of outbound links, many of which point to benign Shopify domains but likely serve to obscure the malicious redirector. The primary intent appears to be social engineering users into visiting the malicious redirector.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=architecture+portfolio+samples+pdf
    • http://files.coefyouth.com/uploads/1/3/1/3/131379692/fagexi.pdf
    • http://files.chicagolandprotectiondogs.com/uploads/1/3/0/7/130776462/tenaw.pdf
    • http://files.championcoffee.com/uploads/1/3/0/8/130814295/1123813.pdf
    • http://files.hillsideanimalhospital.net/uploads/1/3/1/3/131382092/a5e7fbab7866e5c.pdf
    • http://files.stewartislandnews.com/uploads/1/3/1/3/131398378/31b951153.pdf
    • https://cdn.shopify.com/s/files/1/0433/1339/7924/files/botuduzanujipelakup.pdf
    • https://cdn.shopify.com/s/files/1/0434/1920/5789/files/mac_terminal_commands.pdf
    • https://cdn.shopify.com/s/files/1/0431/5476/8021/files/raligene.pdf
    • https://cdn.shopify.com/s/files/1/0428/9105/1161/files/69449279986.pdf
    • https://cdn.shopify.com/s/files/1/0435/1574/0312/files/classes_and_data_abstraction_in_c.pdf
    • https://cdn.shopify.com/s/files/1/0438/5583/9382/files/42565159489.pdf
    • https://cdn.shopify.com/s/files/1/0427/9864/5404/files/82673940591.pdf
    • https://cdn.shopify.com/s/files/1/0433/0323/9840/files/www_craigslist_org_cleveland_ohio.pdf
    • https://cdn.shopify.com/s/files/1/0431/2494/9153/files/2315516980.pdf
    • https://cdn.shopify.com/s/files/1/0431/1056/4002/files/18915213321.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000892b.bin
015a5fbbce6a93694e593ac72ca387bcc8499b74f8cd87620cedf151321f59d5
pdf-font-stream PDF embedded font (sfnt) at offset 0x892B 5384 bytes
font_01_sfnt_off00009b53.bin
1595215d87629b0e1a32e047aed5ad3f6e8948c347d55e1cf3b34d07d5e580db
pdf-font-stream PDF embedded font (sfnt) at offset 0x9B53 10392 bytes