Malicious PDF — malware analysis report

Static analysis result for SHA-256 2941c187cedfc5ab…

MALICIOUS

PDF

59.5 KB Created: 2020-09-02 09:38:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9fbd2f473f6e15d14cd025bec6e3aae8 SHA-1: ef82045d5773d2827697bf89a41e67fcf7b0cf5e SHA-256: 2941c187cedfc5ab72d9fb7f58e9e7266b8fc2712d3b114fae315dfbcdb4761d
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to `https://ttraff.com/wix?keyword=badshah+movie+song+free++2017`. This indicates a social engineering lure, likely attempting to trick users into visiting a malicious site by disguising it as a movie song download. The PDF also contains a link farm, with many links pointing to Shopify and usrfiles.com domains, though these specific domains were labeled as confirmed benign. The document body contains garbled text but includes the malicious URL.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=badshah+movie+song+free++2017
    • https://cdn.shopify.com/s/files/1/0431/7505/1415/files/83524699644.pdf
    • https://cdn.shopify.com/s/files/1/0428/6762/2055/files/77222860008.pdf
    • https://cdn.shopify.com/s/files/1/0429/8126/1466/files/nozufimoripoxa.pdf
    • https://cdn.shopify.com/s/files/1/0429/7211/9199/files/descriptive_analysis_journal.pdf
    • https://cdn.shopify.com/s/files/1/0437/9190/9025/files/kp_astrology_lessons_in_tamil.pdf
    • https://static.usrfiles.com/ugd/9734e7_bcd2bc95b3af427c9380678b44a5a844.pdf
    • https://static.usrfiles.com/ugd/866690_fd46a8a3e9914d72bc86b7b2daa939a7.pdf
    • https://static.usrfiles.com/ugd/f515ca_3bfb2f8f42bd4325825b304940b6f21d.pdf
    • https://static.usrfiles.com/ugd/374ce0_67460854fa934967994fb4f47b2a52b9.pdf
    • https://static.usrfiles.com/ugd/67f5f7_edae88899f7a49bd99a513b5db9eee89.pdf
    • https://static.usrfiles.com/ugd/3eed2b_1ea3646b26de45bba0a4901edb76554b.pdf
    • https://static.usrfiles.com/ugd/3e9e83_84028bbd6173492981b9647cbdc9740c.pdf
    • https://static.usrfiles.com/ugd/b8c837_4c29e3d0697846adb9f06de7e5baf2bc.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007930.bin
32a4ff29ff6b906449d7aa987173dd78ddf71e7aed6c0b30e99f2e8d4adf4ee2
pdf-font-stream PDF embedded font (sfnt) at offset 0x7930 5804 bytes
font_01_sfnt_off00008cdc.bin
be405a587aeb27f2f1c8e01f57f3fc2cb7ca9f049082fb6ffc0c972011581d92
pdf-font-stream PDF embedded font (sfnt) at offset 0x8CDC 7644 bytes
font_02_sfnt_off0000a53c.bin
facfc4466754507c74a17aa8d1c0a93f51145a0cd5b2eb41ea55e43564f881bb
pdf-font-stream PDF embedded font (sfnt) at offset 0xA53C 10624 bytes
font_03_sfnt_off0000c9e5.bin
a31282563bd3a1a6834895838b9854db78bb4665d5617f855f738fbfafc4741a
pdf-font-stream PDF embedded font (sfnt) at offset 0xC9E5 6640 bytes