Malicious PDF — malware analysis report

Static analysis result for SHA-256 3e05365dfa8e00ef…

MALICIOUS

PDF

57.2 KB Created: 2020-09-04 20:14:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 907fd62c0afee6f8ed1e3b0f21a15754 SHA-1: cf7bd66d108a4911220aa039ed436ce3c3cb1f29 SHA-256: 3e05365dfa8e00efc5a4171546ccc0910fb4730c45b7f356ca27e67f6dc92009
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.me/wix?keyword=jquery+ajax+post+form+data'. The document body, though heavily obfuscated, also contains this URL, suggesting it's the primary lure. The file's purpose appears to be directing users to potentially malicious content through this link, disguised as a search result.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=jquery+ajax+post+form+data
    • https://cdn.shopify.com/s/files/1/0427/9674/4871/files/managerial_accounting_asia_global_edition_2e_solutions_manual.pdf
    • https://cdn.shopify.com/s/files/1/0433/8273/5006/files/rurudoboxoneguvi.pdf
    • https://cdn.shopify.com/s/files/1/0430/9850/5369/files/park_big_blue_book_of_bicycle_repair.pdf
    • https://cdn.shopify.com/s/files/1/0433/3826/8827/files/12564367530.pdf
    • https://cdn.shopify.com/s/files/1/0434/2992/0930/files/89620047012.pdf
    • https://static.usrfiles.com/ugd/97634b_1daac07dee4542eea4ccb8d6477deb52.pdf
    • https://static.usrfiles.com/ugd/3b7182_037dee98fae34f52a751442bbfba0ec9.pdf
    • https://static.usrfiles.com/ugd/1d5a3f_81c32855df2a44c8b2fdb008e62e7f23.pdf
    • https://static.usrfiles.com/ugd/bdeb4c_2c11209a32a14ff69d7edb1b6dcaf88e.pdf
    • https://static.usrfiles.com/ugd/ceb2e8_29b2074a7aed4b5eb9c2fa70bebf17a6.pdf
    • https://static.usrfiles.com/ugd/fb5067_d5d000552e7a483ba03631eb152b37d3.pdf
    • https://cdn.shopify.com/s/files/1/0440/4789/2630/files/kambi_katha_malayalam_cartoon.pdf
    • https://cdn.shopify.com/s/files/1/0432/7243/7910/files/75090360304.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com/s/file

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009119.bin
c030c24bd5ba9ce6285738130bf866b4260efefd094c867d0a971ed4f05eda3d
pdf-font-stream PDF embedded font (sfnt) at offset 0x9119 5516 bytes
font_01_sfnt_off0000a3db.bin
301bf6dfd0774725383b968e9bf1f5b8cca059ce3c8796dc4075d5b94e88cd1c
pdf-font-stream PDF embedded font (sfnt) at offset 0xA3DB 16684 bytes