Malicious PDF — malware analysis report

Static analysis result for SHA-256 3a13f6e6af38f101…

MALICIOUS

PDF

45.0 KB Created: 2020-09-01 04:50:18 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 686c2b97af1134ea7ab5982ff935198b SHA-1: 5e608e3fab395cd58b4d827688bd7f08962373e1 SHA-256: 3a13f6e6af38f1010be30d2d2c0388a92efc06ffe0370bfe25b2e3f9fa7ae1aa
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.link/wix?keyword=best+free+weight+lifting+apps+for+android'. This indicates the document's primary purpose is to redirect the user to a malicious site. The PDF also contains a large number of external links, suggesting a link farm or SEO poisoning tactic to attract unsuspecting users.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=best+free+weight+lifting+apps+for+android
    • https://static.usrfiles.com/ugd/e4ff69_3f24aa7dd03347729a296abf31c23d6b.pdf
    • https://static.usrfiles.com/ugd/b8c837_122c8ffb822842fb91337fd11e7ec27c.pdf
    • https://static.usrfiles.com/ugd/2e16aa_01f7c7f5bfec43f691893253f5903091.pdf
    • https://static.usrfiles.com/ugd/ec0c41_0384bdd203e14ed999cf301fee1e18b6.pdf
    • https://cdn.shopify.com/s/files/1/0438/9906/0392/files/87677578282.pdf
    • https://cdn.shopify.com/s/files/1/0454/7847/7976/files/widuraxijevisokerus.pdf
    • https://cdn.shopify.com/s/files/1/0436/0850/6531/files/78751206187.pdf
    • https://cdn.shopify.com/s/files/1/0431/4441/3350/files/lagu_arlida_putri_adella_terbaru.pdf
    • https://cdn.shopify.com/s/files/1/0427/9386/1279/files/potigovigafubuxezurek.pdf
    • https://static.usrfiles.com/ugd/19103d_258d86e9b8614a1195865c7264cccbab.pdf
    • https://static.usrfiles.com/ugd/9e14ca_9c5fad58dcf34dc09cdbbdcbadbdb928.pdf
    • https://static.usrfiles.com/ugd/b8c837_a4ad87bbb5ac45b1b7a6d1efa8027d16.pdf
    • https://static.usrfiles.com/ugd/eaf48f_ce43253dc6654c4eb181a4e7fb9f1f45.pdf
    • https://static.usrfiles.com/ugd/b98abb_b0065992c4b54b719f7695c2549f85fc.pdf
    • https://static.usrfiles.com/ugd/b88e3d_9599634f25cb406288a3cfd15c2d2120.pdf
    • https://static.usrfiles.com/ugd/9cb927_2451ce42896c40048c3b330cc24ac60c.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000701e.bin
eb8f7358cd6001de4ee9911ba642644c7cec74a9f82c862249544aa6732a8246
pdf-font-stream PDF embedded font (sfnt) at offset 0x701E 5444 bytes
font_01_sfnt_off000082b9.bin
1a8aa624066efe2be0a23a2368af6252f35e724f0d8aeec4f97aeb5b6877ea9c
pdf-font-stream PDF embedded font (sfnt) at offset 0x82B9 10980 bytes