Malicious PDF — malware analysis report

Static analysis result for SHA-256 37531e5ccec81b53…

MALICIOUS

PDF

42.0 KB Created: 2020-08-12 20:58:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5189a8e7b42033e90a27c2299fe65d4e SHA-1: 38141541276bd1b9f180e0754a238bd097d3fd92 SHA-256: 37531e5ccec81b537aaffe718836b8a3eee4e03a4964817eb1f00793c0ed2d49
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains multiple embedded URLs, with a critical heuristic firing indicating a link to known malicious redirector infrastructure. The primary malicious URL is https://ttraff.com/wb?keyword=climate%20change%20definition%20geography%20pdf. Another heuristic identified a large number of external PDF links, suggesting a link farm or SEO manipulation tactic. The document body, though heavily obfuscated, also contains the primary malicious URL and several other URLs pointing to Shopify, some of which are benign but others are unknown.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wb?keyword=climate%20change%20definition%20geography%20pdf
    • http://files.thedaveellis.com/uploads/1/3/2/6/132695932/5315098.pdf
    • http://files.vedvalmiki.com/uploads/1/3/1/3/131380258/zidutogaramulemage.pdf
    • http://kepobane.magicofrob.com/uploads/1/3/0/7/130776644/ramaji-bepak-mareko-lixizomev.pdf
    • http://files.decaturcountyworks.com/uploads/1/3/1/4/131453453/muxafukoteluwufo.pdf
    • http://files.dental-medical-connections.com/uploads/1/3/0/8/130813736/wibexamakerab.pdf
    • https://cdn.shopify.com/s/files/1/0437/6238/5045/files/audio_power_amplifier_handbook.pdf
    • https://cdn.shopify.com/s/files/1/0433/1329/9620/files/pubadutizimomima.pdf
    • https://cdn.shopify.com/s/files/1/0431/9094/3901/files/dism._exe_online_cleanup-_image_startcomponentcleanup.pdf
    • https://cdn.shopify.com/s/files/1/0429/8126/1466/files/6235832938.pdf
    • https://cdn.shopify.com/s/files/1/0443/0397/4556/files/lokovopin.pdf
    • https://cdn.shopify.com/s/files/1/0430/4830/4797/files/62309787849.pdf
    • https://cdn.shopify.com/s/files/1/0437/2699/5621/files/89798760183.pdf
    • https://cdn.shopify.com/s/files/1/0432/8095/7598/files/58292835203.pdf
    • https://cdn.shopify.com/s/files/1/0436/6968/4377/files/block_matrix_multiplication.pdf
    • https://cdn.shopify.com/s/files/1/0430/0167/5939/files/zawakimo.pdf
    • https://cdn.shopify.com/s/files/1/0428/4183/3635/files/fosuku.pdf
    • https://cdn.shopify.com/s/files/1/0438/3028/0352/files/neoplasia_maligna.pdf
    • https://cdn.shopify.com/s/files/1/0433/6304/1430/files/kumegeles.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000066f9.bin
63fbda2800acc09180fbd73dff7abce127e82c9d89eecede0c6eaa83a2c7cfaf
pdf-font-stream PDF embedded font (sfnt) at offset 0x66F9 5400 bytes
font_01_sfnt_off0000792e.bin
844284d9797677a9b1e4942c7f11f49effcf7384128f55977356eed2f4620cf8
pdf-font-stream PDF embedded font (sfnt) at offset 0x792E 9896 bytes