Malicious PDF — malware analysis report

Static analysis result for SHA-256 2072bfb2bf2913a9…

MALICIOUS

PDF

37.6 KB Created: 2020-08-30 19:21:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6839a484a0982d05494ec92c0f50c6bd SHA-1: a3d3e1f3ed3fefc8479e25fb85f6ab561be27885 SHA-256: 2072bfb2bf2913a970e6c3b12c854690909266899965bec33fa83173ca12d0ce
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.com/wix?keyword=principles+of+finance+with+excel+benninga'. This indicates the document's primary purpose is to redirect users to a potentially harmful site. The presence of numerous other links, many hosted on cdn.shopify.com, suggests a link farm or SEO poisoning tactic to increase the visibility of the malicious redirector. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=principles+of+finance+with+excel+benninga
    • https://cdn.shopify.com/s/files/1/0432/6519/6197/files/55072035321.pdf
    • https://cdn.shopify.com/s/files/1/0428/5287/6455/files/for_your_improvement_franais.pdf
    • https://cdn.shopify.com/s/files/1/0427/8996/1884/files/gugenupasud.pdf
    • https://cdn.shopify.com/s/files/1/0436/6221/3273/files/7299721948.pdf
    • https://cdn.shopify.com/s/files/1/0428/1712/6563/files/vunalaxirosenewiwaf.pdf
    • https://cdn.shopify.com/s/files/1/0432/1994/3579/files/34057004560.pdf
    • https://cdn.shopify.com/s/files/1/0457/7224/3110/files/young_goodman_brown_questions_and_answers.pdf
    • https://cdn.shopify.com/s/files/1/0431/1737/9750/files/mongodb_atlas_terraform_provider.pdf
    • https://cdn.shopify.com/s/files/1/0438/3752/2085/files/32146766955.pdf
    • https://cdn.shopify.com/s/files/1/0428/3957/2643/files/mimiv.pdf
    • https://static.usrfiles.com/ugd/67f5f7_f87d603beebe4fdfbca41d17f99c5817.pdf
    • https://static.usrfiles.com/ugd/7f46b5_1d890967a2c2472083f74d113f19a41d.pdf
    • https://static.usrfiles.com/ugd/01e791_7142f3abe8bf44509466ee057f2dff56.pdf
    • https://static.usrfiles.com/ugd/b8c837_483394ee66ae42fe82a0d3b3a35fe1b5.pdf
    • https://static.usrfiles.com/ugd/b3bc21_cbf7d298f9c04a33909aaedc9e6563d4.pdf
    • https://static.usrfiles.com/ugd/b8c837_a8f1667d866e4a3aa3ca1cf1a30ec6b5.pdf
    • https://static.usrfiles.com/ugd/c7a620_c8ce626a610340878877bbbd59d156b9.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000057a8.bin
6754a4d0711a9b45cf2414aae66c57b1217bac2b3fe759b4938f7200801c7123
pdf-font-stream PDF embedded font (sfnt) at offset 0x57A8 5580 bytes
font_01_sfnt_off00006aa6.bin
5ed788cf3a83fd3f27c99e821aad330ec811572590aa7c3e1c2e4a723caf6fc9
pdf-font-stream PDF embedded font (sfnt) at offset 0x6AA6 9056 bytes