Malicious PDF — malware analysis report

Static analysis result for SHA-256 d2aec564759e84c0…

MALICIOUS

PDF

49.6 KB Created: 2020-08-09 01:45:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 673983aafeb860c9932633eb7f651b25 SHA-1: fa24d768519f729141f5aaa69fe737e466b71fd9 SHA-256: d2aec564759e84c0539e105f8dd2c25e882f30d6d4765857cb68cd6a941ebe58
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.cc/pify?keyword=acretismo+placentario+pdf+acog'. This URL is designed to redirect users to potentially harmful content. The document also contains a large number of embedded links, many hosted on Shopify, which is characteristic of SEO poisoning or link farm tactics to improve search engine ranking for malicious sites. The document body, though heavily obfuscated, contains the same suspicious URL, reinforcing the lure.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=acretismo+placentario+pdf+acog
    • http://getefuluf.tobypenneyartist.com/uploads/1/3/1/6/131606490/zazonuzejevivimeno.pdf
    • http://files.stitchedwithcare.com/uploads/1/3/1/3/131383624/dowumi-wefudazebukop-wivavin-tajewowe.pdf
    • http://zaparez.retreatjourneys.com/uploads/1/3/1/8/131871721/e8d8501f67923b9.pdf
    • https://cdn.shopify.com/s/files/1/0428/5038/6086/files/25505963990.pdf
    • https://cdn.shopify.com/s/files/1/0430/8847/8359/files/63036147937.pdf
    • https://cdn.shopify.com/s/files/1/0428/9075/6259/files/88296182158.pdf
    • https://cdn.shopify.com/s/files/1/0432/1142/3902/files/80856412946.pdf
    • https://cdn.shopify.com/s/files/1/0431/2072/2080/files/90008312805.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/12584167006.pdf
    • https://cdn.shopify.com/s/files/1/0441/3744/7576/files/anthony_robbins_livros_em.pdf
    • https://cdn.shopify.com/s/files/1/0427/5847/1846/files/10608882452.pdf
    • https://cdn.shopify.com/s/files/1/0434/1897/6408/files/lambda_function_javascript.pdf
    • https://cdn.shopify.com/s/files/1/0431/8196/5474/files/77360165804.pdf
    • https://cdn.shopify.com/s/files/1/0434/3840/7845/files/33375061494.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006f64.bin
4103f12eb2d3fd5ce81f4dfd6de156bb127b7b020113f77f3e4d9c5a57060399
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F64 6416 bytes
font_01_sfnt_off00007f2f.bin
9a123298dbc4e105c7d1b25b659e420c63bede8e2e25c1260b6eb1f0f01b50f7
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F2F 5464 bytes
font_02_sfnt_off000091b1.bin
062dfc0794571ab1d8e1b7b75753766306a036a4aa4e162e119ff2c7a23d97a8
pdf-font-stream PDF embedded font (sfnt) at offset 0x91B1 12204 bytes