Malicious PDF — malware analysis report

Static analysis result for SHA-256 7ae2272ac4cab160…

MALICIOUS

PDF

231.4 KB Created: 2020-08-06 20:21:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 1ce4a6dfe76c66c30a0368544377f840 SHA-1: 8d1046af2aaccec87fe4f21aff6a7878976b45e5 SHA-256: 7ae2272ac4cab160b302ce9be17c86bf1f495d43f7fb66d033e27bfea570c580
68 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious Link T1566.002 Spearphishing Attachment

The PDF contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/pify?keyword=apple+inc+company+profile+pdf'. Additionally, a low-signal heuristic for a 'Download Button' was observed. The document body, though heavily obfuscated, also contains the same malicious URL. This suggests the document's primary purpose is to trick the user into clicking the link, leading them to a malicious site.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=apple+inc+company+profile+pdf
    • http://files.jilanalbayyat.com/uploads/1/3/0/7/130775916/7858120.pdf
    • http://files.xn--ettrfrdjuren-vcb4v.se/uploads/1/3/0/8/130814769/3906374.pdf
    • http://files.all2run.com/uploads/1/3/1/8/131871535/e700c947.pdf
    • http://files.guqintables.com/uploads/1/3/1/3/131381919/tutafuli.pdf
    • https://cdn.shopify.com/s/files/1/0434/6331/1520/files/80536004568.pdf
    • https://cdn.shopify.com/s/files/1/0435/4736/1439/files/ashrae_handbook_refrigeration_systems_and_applications.pdf
    • https://cdn.shopify.com/s/files/1/0432/4032/5282/files/definition_of_economics_by_ten_different_authors.pdf
    • https://cdn.shopify.com/s/files/1/0432/6598/2632/files/xujimujipubumug.pdf
    • https://cdn.shopify.com/s/files/1/0437/2283/4071/files/40356796146.pdf
    • https://cdn.shopify.com/s/files/1/0434/7183/1193/files/23662361283.pdf
    • https://cdn.shopify.com/s/files/1/0439/9949/4302/files/20053434335.pdf
    • https://cdn.shopify.com/s/files/1/0440/9124/4696/files/nuduwunenose.pdf
    • https://cdn.shopify.com/s/files/1/0428/5880/7455/files/72126345400.pdf
    • https://cdn.shopify.com/s/files/1/0434/7202/7814/files/pifukepaloramoxokapu.pdf
    • https://cdn.shopify.com/s/files/1/0438/4784/4000/files/piradufuxozoxoxoded.pdf
    • https://cdn.shopify.com/s/files/1/0430/7209/4362/files/3004832284.pdf
    • https://cdn.shopify.com/s/files/1/0433/2693/1099/files/differences_between_business_administration_and_business_management.pdf
    • https://cdn.shopify.com/s/files/1/0432/0965/4436/files/6317798792.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00033922.bin
bb1a25466c3558164d80eaa524958924b3ae2195a827ad38d7b70e8863f4fae5
pdf-font-stream PDF embedded font (sfnt) at offset 0x33922 3460 bytes
font_01_sfnt_off00034571.bin
cb633977ef5dd8ffff926a06a116b2765f1f512e27701646a5523c9cdd51c127
pdf-font-stream PDF embedded font (sfnt) at offset 0x34571 5212 bytes
font_02_sfnt_off0003571b.bin
57a58d4991e9fa9a666ad7337bb86d312f0c6b4dee5ebc3050e57f93cb5df23e
pdf-font-stream PDF embedded font (sfnt) at offset 0x3571B 2628 bytes
font_03_sfnt_off00036234.bin
a671e9fa6ab2ebee9ca5caa3342c35bd60debee121cdbc282d1bd318be9dd5cb
pdf-font-stream PDF embedded font (sfnt) at offset 0x36234 13676 bytes