Malicious PDF — malware analysis report

Static analysis result for SHA-256 20e88533963bee7f…

MALICIOUS

PDF

48.7 KB Created: 2020-08-30 02:40:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 92dd737ec5ef7ff40a2b21a4e2204aa5 SHA-1: 94c3f86d8c2d8b007e69684119e9d076f99c728e SHA-256: 20e88533963bee7f4476cdf91845d046ec9946fe6e87d420f04d17433810b8de
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.link/wix?keyword=ac+dc+highway+to+hell+live+at+river+plate+hd'. This URL is embedded within the document's body, suggesting a social engineering attempt to trick users into visiting a potentially harmful site. The file also exhibits characteristics of a PDF SEO link farm, with numerous links to external PDFs, many hosted on cdn.shopify.com and static.usrfiles.com. While some linked PDFs are benign, the primary redirector link is the highest priority IOC.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=ac+dc+highway+to+hell+live+at+river+plate+hd
    • https://static.usrfiles.com/ugd/1d64af_be78d44141a54e72a3cda6673d9bb989.pdf
    • https://static.usrfiles.com/ugd/b8c837_db5ce2301eab471998b6d72e6d83ad04.pdf
    • https://static.usrfiles.com/ugd/b8c837_502f1399816e44929536504239af61e2.pdf
    • https://cdn.shopify.com/s/files/1/0432/3131/4077/files/ultimate_manicure_system.pdf
    • https://cdn.shopify.com/s/files/1/0440/7007/6566/files/ziwenegetafarira.pdf
    • https://cdn.shopify.com/s/files/1/0434/5023/7085/files/1487038567.pdf
    • https://cdn.shopify.com/s/files/1/0433/9440/0414/files/alter_ego_3_vk.pdf
    • https://cdn.shopify.com/s/files/1/0437/2060/5848/files/radiological_anatomy_of_liver.pdf
    • https://static.usrfiles.com/ugd/cafc24_1ba23c2552664af482785491d8f92f58.pdf
    • https://static.usrfiles.com/ugd/b8c837_439ca287ba404a629e4fd1e99a16ca19.pdf
    • https://static.usrfiles.com/ugd/538d67_16faca99480d4f6b918ae26026179586.pdf
    • https://static.usrfiles.com/ugd/bb13a2_f6487a6197fc4847b11d3685eaf62b6e.pdf
    • https://cdn.shopify.com/s/files/1/0431/5702/9018/files/fijaguwavafipufu.pdf
    • https://cdn.shopify.com/s/files/1/0433/7257/6922/files/wetaximi.pdf
    • https://cdn.shopify.com/s/files/1/0428/5677/5839/files/likofum.pdf
    • https://cdn.shopify.com/s/files/1/0436/9124/5733/files/wwe_13_roster.pdf
    • https://cdn.shopify.com/s/files/1/0432/9635/8565/files/hey_listen_mp3.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007cea.bin
b7a00bf56e03370f4f4c3bf5436d27dedd2a2a54e5b47c1dec133de7a5d6126b
pdf-font-stream PDF embedded font (sfnt) at offset 0x7CEA 5400 bytes
font_01_sfnt_off00008f4e.bin
14db265301c21925816ee04732a3ad2a5369fd3dee01643932847a64139a1e4e
pdf-font-stream PDF embedded font (sfnt) at offset 0x8F4E 11428 bytes