Malicious PDF — malware analysis report

Static analysis result for SHA-256 2f9cebe9a61a45a6…

MALICIOUS

PDF

40.3 KB Created: 2020-08-31 07:04:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4e5f20a03c0fee3326c59cc30e0378ca SHA-1: e196f665ffd26bc5f8ebfe1f263b7768cde5a305 SHA-256: 2f9cebe9a61a45a61adce76a5473f006e988b1d26fdc742335b31f4992362617
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a significant number of embedded links, many pointing to Shopify domains, but one critical link directs to a known malicious redirector at 'ttraff.com'. This suggests a link farm or SEO poisoning tactic designed to funnel users to malicious infrastructure. The document body, though heavily obfuscated, contains the malicious URL and several benign-looking PDF links, reinforcing the lure. No scripts were extracted, and the primary malicious activity observed is the redirection to a harmful URL.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=guias+del+cenetec
    • https://cdn.shopify.com/s/files/1/0430/8402/1921/files/34222015020.pdf
    • https://cdn.shopify.com/s/files/1/0431/1603/6249/files/37543190366.pdf
    • https://cdn.shopify.com/s/files/1/0430/6986/6138/files/tolulerubamo.pdf
    • https://cdn.shopify.com/s/files/1/0433/0641/8331/files/materi_sintesis_protein_lengkap.pdf
    • https://static.usrfiles.com/ugd/ce14f3_68ad507b36bd434c96c248e298d70129.pdf
    • https://cdn.shopify.com/s/files/1/0434/4456/8216/files/cold_hearted_snake_lyrics.pdf
    • https://cdn.shopify.com/s/files/1/0433/1808/3742/files/assyrian_language.pdf
    • https://cdn.shopify.com/s/files/1/0432/5575/9011/files/sulikafusulalip.pdf
    • https://cdn.shopify.com/s/files/1/0430/5597/2501/files/fezopa.pdf
    • https://cdn.shopify.com/s/files/1/0435/3520/4511/files/vectors_in_java.pdf
    • https://cdn.shopify.com/s/files/1/0441/1251/1128/files/anime_minecraft_mods.pdf
    • https://cdn.shopify.com/s/files/1/0463/3133/0721/files/88366054568.pdf
    • https://cdn.shopify.com/s/files/1/0437/9879/0301/files/9923063337.pdf
    • https://cdn.shopify.com/s/files/1/0439/7573/7502/files/conditional_operator_in_c_example.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004b36.bin
1cbd27995e7dc1f8174b3579896973cc53d9c661ddba93edd468af2394d42168
pdf-font-stream PDF embedded font (sfnt) at offset 0x4B36 4868 bytes
font_01_sfnt_off00005bd0.bin
c77fcb9a7c024893bbecc41e2c5188a3e6e93bc58d179bddc30bd456659df41d
pdf-font-stream PDF embedded font (sfnt) at offset 0x5BD0 10216 bytes
font_02_sfnt_off00007d2c.bin
f267a97a42ed964490c0c36cf8d24d30f5cfc386ee24850e75bb3a4991f11828
pdf-font-stream PDF embedded font (sfnt) at offset 0x7D2C 16376 bytes