Malicious PDF — malware analysis report

Static analysis result for SHA-256 3171efee2c42fa8d…

MALICIOUS

PDF

52.1 KB Created: 2020-08-09 13:58:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5f8ec69f75f63e5066def9c234005655 SHA-1: 6c9314ebb5e52e043635e769abc47fd24e1c3d04 SHA-256: 3171efee2c42fa8d98af218824947a886e4eb098ea34a87107a97d602ed13c60
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a link to a known malicious redirector, ttraff.cc, which is designed to lead users to malicious content. The document body, though heavily obfuscated, contains the same URL. The presence of numerous external links, many pointing to Shopify domains, suggests a link farm or SEO poisoning tactic to increase visibility and lure unsuspecting users. The file was generated by wkhtmltopdf, indicating it's likely a crafted document rather than a legitimate one.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=how+to+use+digital+multimeter+dt9205a+pdf
    • http://files.familyandbusinesslearning.com/uploads/1/3/1/4/131452846/3631894.pdf
    • http://musul.millercounselingserv.com/uploads/1/3/2/8/132814930/gexoxito-lamagijopevi-jisevuro.pdf
    • http://files.muskokapride.com/uploads/1/3/0/8/130815437/2943325.pdf
    • http://files.wearephysicaltherapy.com/uploads/1/3/0/9/130969889/madoguzemum-kasozonafowe-gelizemeke-bejakopalanoda.pdf
    • http://files.wearephysicaltherapy.com/uploads/1/3/0/9/130969889/madoguzemum-kas
    • https://cdn.shopify.com/s/files/1/0432/1941/9291/files/93079723823.pdf
    • https://cdn.shopify.com/s/files/1/0431/6043/6896/files/vinifepoputo.pdf
    • https://cdn.shopify.com/s/files/1/0431/3900/6632/files/winston_operations_research_solutions_manual.pdf
    • https://cdn.shopify.com/s/files/1/0429/7365/9290/files/zalos.pdf
    • https://cdn.shopify.com/s/files/1/0431/7862/3138/files/79538933589.pdf
    • https://cdn.shopify.com/s/files/1/0427/5961/8716/files/62082174688.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/69440205977.pdf
    • https://cdn.shopify.com/s/files/1/0431/8819/1396/files/97135160363.pdf
    • https://cdn.shopify.com/s/files/1/0431/8773/2644/files/butukiviwuzasiz.pdf
    • https://cdn.shopify.com/s/files/1/0434/9083/6645/files/15888513588.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000077f6.bin
2bc90853f759386b274a780a41bea4d768b7e1786905e065f3332a95ba5b650f
pdf-font-stream PDF embedded font (sfnt) at offset 0x77F6 5968 bytes
font_01_sfnt_off00008bfe.bin
21b234704848fbecab0a56cb0868772fe580bb687489ad2b6fb3f3f80534b503
pdf-font-stream PDF embedded font (sfnt) at offset 0x8BFE 6252 bytes
font_02_sfnt_off00009b2a.bin
c57414f652ac714f41d212d4350c351608b893055e03d355a8fa9c756cdc84f8
pdf-font-stream PDF embedded font (sfnt) at offset 0x9B2A 11240 bytes