Malicious PDF — malware analysis report

Static analysis result for SHA-256 415da06c79f0f404…

MALICIOUS

PDF

57.0 KB Created: 2020-08-29 19:19:12 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 937d8339040170f5150ebc634647bb42 SHA-1: 32854d004163c3bfd231d556ac5b93cfc507ee11 SHA-256: 415da06c79f0f404f71bcfe362b78ee48ea0bd903ca6ddd054641a2e906f6a34
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains numerous embedded links, with a critical heuristic firing indicating a malicious redirector link to 'ttraff.com'. Another critical heuristic identified a PDF link farm, suggesting the document's primary purpose is to host a large number of external links. While the document body is heavily obfuscated, the presence of these links and the malicious redirector strongly indicate an attempt to lure users to potentially harmful content, possibly for SEO manipulation or to serve further malicious payloads.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=spring+mvc+tutorial+with+eclipse+and
    • https://cdn.shopify.com/s/files/1/0431/8887/9521/files/47000254386.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/20726054751.pdf
    • https://cdn.shopify.com/s/files/1/0432/8023/6702/files/import_data_from_excel_sheet_to_r.pdf
    • https://cdn.shopify.com/s/files/1/0433/9020/6119/files/roxirajurubiguminu.pdf
    • https://cdn.shopify.com/s/files/1/0440/3943/8486/files/pokemon_sun_and_moon_animated_sprites.pdf
    • https://static.usrfiles.com/ugd/b8c837_5fd98ab8379b47ddb5271056b0ae102f.pdf
    • https://static.usrfiles.com/ugd/b8c837_25449e10606b4d90bb17b4753bd07f7f.pdf
    • https://static.usrfiles.com/ugd/b8c837_e285629aa57b4869b8e57c127a89b030.pdf
    • https://static.usrfiles.com/ugd/89064d_0163f3ff862e4917aeb820d584a3da9d.pdf
    • https://static.usrfiles.com/ugd/6da380_1ee4b15dfe9845e88c19f607d9481db9.pdf
    • https://static.usrfiles.com/ugd/b8c837_370d3142b2dd427b91091a4ecdfb54ec.pdf
    • https://static.usrfiles.com/ugd/b8c837_b7404dad5f7546aeaea5af6da0a6de0b.pdf
    • https://static.usrfiles.com/ugd/6da380_618520f9836441efa96cff3c177f9c65.pdf
    • https://static.usrfiles.com/ugd/b8c837_c511eeff4e23487ba470335c65a80620.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000669a.bin
3377f9ee96f195d205ba6c09af517c800cbf7a5d7af16999688a1c75fdd47443
pdf-font-stream PDF embedded font (sfnt) at offset 0x669A 5624 bytes
font_01_sfnt_off0000798f.bin
a36eee06fef6ce219692c4ec918276ac99413e4fd1e3666e4031624f9289d620
pdf-font-stream PDF embedded font (sfnt) at offset 0x798F 1800 bytes
font_02_sfnt_off0000821c.bin
f01d3ba0e0c8ca2e7e255dd3c8d4ff39d7b23a068cfd76182607cdf04c6e3868
pdf-font-stream PDF embedded font (sfnt) at offset 0x821C 15704 bytes
font_03_sfnt_off0000b2eb.bin
e93acd332f5893643511f4cefd38969ad5c744ad1b08842a788b6be7d277dd15
pdf-font-stream PDF embedded font (sfnt) at offset 0xB2EB 16204 bytes
font_04_sfnt_off0000c819.bin
9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2
pdf-font-stream PDF embedded font (sfnt) at offset 0xC819 4324 bytes