Malicious PDF — malware analysis report

Static analysis result for SHA-256 2094a1ac85a1eca1…

MALICIOUS

PDF

43.4 KB Created: 2020-08-29 01:09:41 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4814d0a401e43dc0a2ac850ce3b10df7 SHA-1: c72c8f914cb32d0efcddcbe8a99f0eb38ca2ae91 SHA-256: 2094a1ac85a1eca1c4069261fd82ffe38de4cfd04491e72bdf5c6ecc3d6e44a8
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.com/wix?keyword=john+wick+mp4+download'. This suggests the document's primary purpose is to trick users into clicking this link, likely for malicious purposes. The document body also contains this URL, reinforcing the lure. The file also exhibits characteristics of a PDF link farm, with numerous embedded links, though most resolve to benign content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=john+wick+mp4+download
    • https://static.usrfiles.com/ugd/b8c837_1ff2533c4c3f4d0db9f272b2c5c62050.pdf
    • https://static.usrfiles.com/ugd/b8c837_d3c1d65ba4fa411aa6448037372a4910.pdf
    • https://static.usrfiles.com/ugd/b8c837_eea4112683c54a28bbe9606a482bf2ab.pdf
    • https://static.usrfiles.com/ugd/b8c837_f29b2a0d105f4ecba9aed31dac4f6fbc.pdf
    • https://static.usrfiles.com/ugd/b8c837_25ce794ea87541828f2e8ce8877a5f8f.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/zafon.pdf
    • https://cdn.shopify.com/s/files/1/0432/8967/3888/files/bitmap_books.pdf
    • https://cdn.shopify.com/s/files/1/0431/1403/7397/files/aprendizajes_clave_ciencias_y_tecnologia_educacion_secundaria.pdf
    • https://cdn.shopify.com/s/files/1/0433/0238/7867/files/madiravisokesapopu.pdf
    • https://cdn.shopify.com/s/files/1/0428/0962/2691/files/67329414420.pdf
    • https://static.usrfiles.com/ugd/b8c837_7153104b2f4e4ed4bfcd29b37267f57e.pdf
    • https://static.usrfiles.com/ugd/b8c837_c0b9f2e80a844d1cba436aabd9056d62.pdf
    • https://static.usrfiles.com/ugd/b8c837_db9b540fbbe147f8a512187bec583164.pdf
    • https://cdn.shopify.com/s/files/1/0433/4069/3662/files/nozubogaxaxituruxukep.pdf
    • https://cdn.shopify.com/s/files/1/0453/3600/2715/files/definite_indefinite_zero_articles_exercises.pdf
    • https://cdn.shopify.com/s/files/1/0432/4841/8973/files/encounter_shankar_movie_song_free.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005f1e.bin
dcacff832f87b40a43a7d2ada38f114e6dab28f8f2c9036a4df5bace26ecd6a6
pdf-font-stream PDF embedded font (sfnt) at offset 0x5F1E 4864 bytes
font_01_sfnt_off00006f7b.bin
ed78f80b0bf44aa1d6b5d4b82df576b89ffb0f04302e4972c4b56dbc5300849c
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F7B 10352 bytes
font_02_sfnt_off00009302.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0x9302 4324 bytes