Malicious PDF — malware analysis report

Static analysis result for SHA-256 9fbf72c4779d9e78…

MALICIOUS

PDF

43.0 KB Created: 2020-08-18 18:49:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6ed1723270d5162ae0e7cd000fe9e321 SHA-1: eebe5143025d57a8b763e8cd995ae2fc7c7fd4e8 SHA-256: 9fbf72c4779d9e78dfe536490dfe11bea15c7c1b669e529575989f3026dcfa90
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains embedded links, one of which points to a known malicious redirector. The document body, though partially corrupted, suggests a lure related to FHA guidelines on rental income, likely intended to trick users into clicking the malicious link. The presence of numerous external PDF links, many hosted on Shopify, further indicates a link farm or SEO poisoning attempt to drive traffic to the malicious redirector.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=fha+guidelines+on+departing+residence+rental+income
    • http://files.bearsneststudio.com/uploads/1/3/0/8/130874633/2423468.pdf
    • http://nekiwubux.janeandandrew.net/uploads/1/3/2/6/132682076/2781466.pdf
    • http://files.presentationsistersnz.com/uploads/1/3/1/4/131438079/feroponuxen-tifokozaduno-luwamig.pdf
    • http://navoge.rhetinfo.com/uploads/1/3/1/3/131383483/d2106efd6e.pdf
    • http://files.elenamccown.com/uploads/1/3/2/7/132712129/ruwosakedodiloku.pdf
    • https://cdn.shopify.com/s/files/1/0430/8529/9874/files/samsung_galaxy_app_store.pdf
    • https://cdn.shopify.com/s/files/1/0433/6612/1623/files/estados_financieros_tesis.pdf
    • https://cdn.shopify.com/s/files/1/0431/8432/4770/files/8938422475.pdf
    • https://cdn.shopify.com/s/files/1/0435/3084/6363/files/98374575195.pdf
    • https://cdn.shopify.com/s/files/1/0435/7180/6366/files/ruguf.pdf
    • https://cdn.shopify.com/s/files/1/0440/7836/6885/files/50179131769.pdf
    • https://cdn.shopify.com/s/files/1/0431/2478/5319/files/bemba_english_dictionary_download.pdf
    • https://cdn.shopify.com/s/files/1/0434/5410/3713/files/gobulexuvokiletuma.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/8917749958.pdf
    • https://cdn.shopify.com/s/files/1/0433/9063/2092/files/46810004911.pdf
    • https://cdn.shopify.com/s/files/1/0433/3993/9994/files/apttus_cpq_admin_guide.pdf
    • https://cdn.shopify.com/s/files/1/0430/2834/9085/files/gafewuvejas.pdf
    • https://cdn.shopify.com/s/files/1/0434/9739/0244/files/8_beatitudes_and_their_meaning.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000698b.bin
4cd82547699accef5a32921d75e96883cb7b3c5501de46315defc62dbcb51eac
pdf-font-stream PDF embedded font (sfnt) at offset 0x698B 5444 bytes
font_01_sfnt_off00007be1.bin
5d7a24313f7f9f6a9a17d2d0da8bc48cbb8899d2258380d07556dd6e0cbca327
pdf-font-stream PDF embedded font (sfnt) at offset 0x7BE1 10212 bytes