Malicious PDF — malware analysis report

Static analysis result for SHA-256 c246659336c7bd96…

MALICIOUS

PDF

36.1 KB Created: 2020-08-22 06:58:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e6b8280ef6ccff23e406110a48bc836a SHA-1: d0b1fd8cbc0aa849dfe617f00961c6d7cb86b2d3 SHA-256: c246659336c7bd96a2a9b504b505d2123d94082e48ff6e2c64ce35c8128196f7
142 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 User Execution: Malicious Link

The PDF file contains a heuristic firing indicating it links to known malicious redirector infrastructure. The document body, though heavily obfuscated, contains text related to 'Fairfield county ohio accident reports' and includes the malicious URL. This suggests a lure to redirect users to potentially harmful content. The presence of numerous external PDF links also points to a link farm strategy.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=fairfield+county+ohio+accident+reports
    • http://files.wildcatbands.org/uploads/1/3/1/4/131407625/kewikalof-dugog-tegonivatujan-tuwonudukuwugi.pdf
    • http://files.womens4miler.org/uploads/1/3/0/7/130739596/6379254.pdf
    • http://maribina.owlwisdomhealing.com/uploads/1/3/0/8/130813077/sovosekufixega_misupisux.pdf
    • http://xufax.inkonivory.ca/uploads/1/3/0/8/130873782/6620083.pdf
    • https://cdn.shopify.com/s/files/1/0431/5653/7493/files/58790522783.pdf
    • https://cdn.shopify.com/s/files/1/0446/9604/3674/files/affiliative_leadership_style.pdf
    • https://cdn.shopify.com/s/files/1/0432/9832/4640/files/2777850670.pdf
    • https://cdn.shopify.com/s/files/1/0437/2443/9704/files/30058883123.pdf
    • https://cdn.shopify.com/s/files/1/0434/8710/1094/files/64571787011.pdf
    • https://cdn.shopify.com/s/files/1/0428/8947/8307/files/vatijejitutuwe.pdf
    • https://cdn.shopify.com/s/files/1/0436/9973/2633/files/katisuni.pdf
    • https://cdn.shopify.com/s/files/1/0432/1335/7214/files/60840472385.pdf
    • https://cdn.shopify.com/s/files/1/0466/2840/5413/files/worksheetfunction_vba_max.pdf
    • https://cdn.shopify.com/s/files/1/0439/1036/5339/files/statistical_modelling_in_pharmaceutical_research_and_development.pdf
    • https://cdn.shopify.com/s/files/1/0430/8205/5842/files/80647070108.pdf
    • https://cdn.shopify.com/s/files/1/0438/0796/5345/files/lipitor_davis.pdf
    • https://cdn.shopify.com/s/files/1/0435/1570/7551/files/nimetefosugezisulupeleg.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/vunazazaxukatokezidabu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004e81.bin
a062a58ee3ebb0afb4ccf89db0a3c35e2e16e48e8bddb943c448bcf8821548c9
pdf-font-stream PDF embedded font (sfnt) at offset 0x4E81 5300 bytes
font_01_sfnt_off00006083.bin
4c433f425d639735b6e772c6397dab38c8e49a5fe848c4e768eb77fd2ffa6260
pdf-font-stream PDF embedded font (sfnt) at offset 0x6083 10148 bytes