Malicious PDF — malware analysis report

Static analysis result for SHA-256 42c0066341bac608…

MALICIOUS

PDF

50.9 KB Created: 2020-08-30 19:55:46 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ffbc2a4bf212764739782002090f2090 SHA-1: da4943ff151ad93700e3ba514c72627a349c0ba3 SHA-256: 42c0066341bac6089241e6f2bf87908f690610203d4bedf06a66c06456df2098
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous embedded links, with one heuristic specifically identifying a link to a known malicious redirector at 'ttraff.com'. The document body, though partially corrupted, includes text suggesting a lure related to 'competition math for middle school pdf'. The presence of a link farm heuristic further indicates a malicious intent to redirect users to external sites.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=competition+math+for+middle+school+pdf
    • https://cdn.shopify.com/s/files/1/0430/2995/4721/files/hill_climb_racing_2_cheats.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/jikas.pdf
    • https://cdn.shopify.com/s/files/1/0464/7383/8744/files/45446475005.pdf
    • https://cdn.shopify.com/s/files/1/0435/7763/9075/files/order_of_adjectives_worksheet_for_high_school.pdf
    • https://cdn.shopify.com/s/files/1/0430/3588/5725/files/83183148977.pdf
    • https://cdn.shopify.com/s/files/1/0451/3175/9769/files/ryobi_chainsaw_manual_petrol.pdf
    • https://cdn.shopify.com/s/files/1/0435/8098/1407/files/67564196589.pdf
    • https://static.usrfiles.com/ugd/b8c837_ef533f54c95f4070b708a506e7d2da2d.pdf
    • https://static.usrfiles.com/ugd/b8c837_22c1acb15cc04f75ac95ba38cce19552.pdf
    • https://static.usrfiles.com/ugd/b8c837_dd3f338279524cbdb4d0238203f1e331.pdf
    • https://static.usrfiles.com/ugd/97368a_23f30db519094205a32bddd2fa4f506a.pdf
    • https://static.usrfiles.com/ugd/47b1e8_9504968889844fe4a72391f27b65610b.pdf
    • https://static.usrfiles.com/ugd/b8c837_c339c8983be644e3b4c99bf180b96e90.pdf
    • https://static.usrfiles.com/ugd/6f53d7_1162cf211150419f834f077e385df7ad.pdf
    • https://static.usrfiles.com/ugd/09273f_b502ae2218db4e7d93e4d0b648d32797.pdf
    • https://static.usrfiles.com/ugd/47b1e8_87c8955f5e2c4989bf61e4b1fd4eb181.pdf
    • https://static.usrfiles.com/ugd/b8c837_ca7214c10c1b47438db081708e9ff2ce.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000088be.bin
32ba9986a0ea79ca8a1f867365aa6396e9a76a46b7c7590d9754c65ce35d66f0
pdf-font-stream PDF embedded font (sfnt) at offset 0x88BE 5300 bytes
font_01_sfnt_off00009a8f.bin
d54c3771792a4c8bf7d08288c858ca4efb104e31817b750ac0a782c1bb456218
pdf-font-stream PDF embedded font (sfnt) at offset 0x9A8F 10412 bytes