Malicious PDF — malware analysis report

Static analysis result for SHA-256 9cc14912576b1a05…

MALICIOUS

PDF

44.4 KB Created: 2020-08-21 03:22:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5eec46cbaf19e7a88d6500d0cc86671d SHA-1: f75228a4eef6ba121143cc7d15e7b7be4eb03d4f SHA-256: 9cc14912576b1a059371646096be83ad3b8dae2b3ae84ad4bc27700282ff4237
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, many of which point to Shopify domains hosting other PDFs, suggesting a link farm for SEO poisoning. One critical heuristic identified a link to a known malicious redirector at 'https://ttraff.com/pify?keyword=reusable+baking+paper+sheets'. The document body, though heavily obfuscated, contains this URL and other PDF links, indicating a social engineering attempt to drive traffic to malicious infrastructure.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=reusable+baking+paper+sheets
    • http://files.capitalfinancialplanningcharitablefoundation.com/uploads/1/3/1/4/131437669/9624467.pdf
    • http://zosen.greenblackdress.com/uploads/1/3/1/4/131407405/60201ff.pdf
    • https://cdn.shopify.com/s/files/1/0429/7906/6009/files/fezumikunilaratit.pdf
    • https://cdn.shopify.com/s/files/1/0440/8298/7158/files/the_communicative_grammar_of_english_workbook_answers.pdf
    • https://cdn.shopify.com/s/files/1/0437/6815/2216/files/a_hat_in_time_modding_tutorial.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/60801944673.pdf
    • https://cdn.shopify.com/s/files/1/0437/3712/0933/files/54314857303.pdf
    • https://cdn.shopify.com/s/files/1/0439/1819/6891/files/revista_natura_ciclo_8_2020.pdf
    • https://cdn.shopify.com/s/files/1/0431/5955/2166/files/penivojawij.pdf
    • https://cdn.shopify.com/s/files/1/0433/3741/6869/files/xuwixadisowewotuxeko.pdf
    • https://cdn.shopify.com/s/files/1/0436/6640/7589/files/java_method_signatures.pdf
    • https://cdn.shopify.com/s/files/1/0440/3625/9990/files/dmv_california_practice_test_2016.pdf
    • https://cdn.shopify.com/s/files/1/0435/3097/7431/files/ad_blocker_free_ios.pdf
    • https://cdn.shopify.com/s/files/1/0430/1049/0519/files/compendio_de_apologetica_catolica_jose_miguel_arraiz.pdf
    • https://cdn.shopify.com/s/files/1/0433/0255/1716/files/zezepidexonavigezo.pdf
    • https://cdn.shopify.com/s/files/1/0429/8512/8090/files/76822507991.pdf
    • https://cdn.shopify.com/s/files/1/0437/5625/7441/files/69475992943.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000063f3.bin
f8e1067525ee8044809d1ac9159be7d557cc424dc116f911c6677d0fe5243504
pdf-font-stream PDF embedded font (sfnt) at offset 0x63F3 5292 bytes
font_01_sfnt_off000075da.bin
c60a881e71c4d557745100e696ed4110551289ba70b5814ae4c2ba4364d96f06
pdf-font-stream PDF embedded font (sfnt) at offset 0x75DA 4580 bytes
font_02_sfnt_off00008236.bin
65af334f7971548dd65b500fcd5668db3571738e809fe9275b27518fc8c4f5d0
pdf-font-stream PDF embedded font (sfnt) at offset 0x8236 9932 bytes