Malicious PDF — malware analysis report

Static analysis result for SHA-256 4077f404728a06b7…

MALICIOUS

PDF

47.9 KB Created: 2020-08-29 21:04:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 84a5bf8b1fe27ee411721b2e9b534c1d SHA-1: 3af8079dbd5e145bef0955baec58b478b0c4c20c SHA-256: 4077f404728a06b7a3dd68fdbc7f88eaf512c5d50876dbc894fc18a43aae2f5e
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to a URL that appears to be a lure for educational content. The document body, though heavily obfuscated, contains references to this URL and a large number of other URLs hosted on Shopify and static.usrfiles.com, suggesting a link farm or SEO poisoning tactic. The primary malicious URL is `https://ttraff.cc/wix?keyword=lesson+10.+2+practice+a+geometry+answers`, which is likely used to redirect users to a malicious site. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=lesson+10.+2+practice+a+geometry+answers
    • https://cdn.shopify.com/s/files/1/0430/9850/5369/files/mobility_scooter_repair_manual.pdf
    • https://cdn.shopify.com/s/files/1/0430/9339/3557/files/wuweroxuwufaxuze.pdf
    • https://cdn.shopify.com/s/files/1/0438/4066/7798/files/psychology_pre_test.pdf
    • https://static.usrfiles.com/ugd/b8c837_dda40266564a42a2a011b4c308ba3623.pdf
    • https://static.usrfiles.com/ugd/b8c837_be15e82486eb4077ada1821a06a4844a.pdf
    • https://static.usrfiles.com/ugd/ace02d_e7105a9f4c41452fa6f103bb834e545c.pdf
    • https://static.usrfiles.com/ugd/b8c837_119944b4b5ee4258828b5250fe89c084.pdf
    • https://static.usrfiles.com/ugd/b8c837_a3bcece0ea7d4d40863468a3da084ff0.pdf
    • https://static.usrfiles.com/ugd/906e9f_d730fedcc3694678b8cfbd38fca95b08.pdf
    • https://static.usrfiles.com/ugd/b8c837_6902fd47bee947a9aeb8e43c9f1216b1.pdf
    • https://static.usrfiles.com/ugd/63d3ad_235a8c75451a4502aa895cc8ae534bf3.pdf
    • https://static.usrfiles.com/ugd/b8c837_66c63703024c45c3942bc6ac7713b1aa.pdf
    • https://static.usrfiles.com/ugd/b8c837_e02019584a954817afa1533844b0729b.pdf
    • https://static.usrfiles.com/ugd/b8c837_abb715f4e3aa43a9b7a73ebd4768e94e.pdf
    • https://static.usrfiles.com/ugd/b8c837_067fd5a819054fd1a5076994dc77ec65.pdf
    • https://static.usrfiles.com/ugd/b8c837_d349c48c4b87436dbe84a3b9d143293c.pdf
    • https://static.usrfiles.com/ugd/b8c837_a8132269b2054bcd8464b320a2d9008d.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://static.usrfiles.com/ugd/b8c837_a8132269b2054bcd8464b32

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007ab0.bin
ab6ec6813e81ad7ab8ec3f606381f753b61f087a1d0adc94b40705cdc689c459
pdf-font-stream PDF embedded font (sfnt) at offset 0x7AB0 5712 bytes
font_01_sfnt_off00008e31.bin
b20199d4dd987a26e6b5b3f11f1e6202095873548fee0b53f45494aa1079948e
pdf-font-stream PDF embedded font (sfnt) at offset 0x8E31 10716 bytes