Malicious PDF — malware analysis report

Static analysis result for SHA-256 476b55b044f19637…

MALICIOUS

PDF

57.7 KB Created: 2020-09-23 12:56:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 762c7f4ab6b120d9b983c87a0893622a SHA-1: 40939ac60055388890b4a3ffd77acaec7a901f09 SHA-256: 476b55b044f196379fdabb494dc22e59d40e6af922d04b9288e31b6af13e1d50
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.me/wix?keyword=movierulz+ms+sahoo'. Additionally, it exhibits a PDF link farm structure with numerous external links, including one to 'https://bda3d5e3-80c1-45d8-9d73-c46e4bf76222.filesusr.com/ugd/dad7b5_1ea5a27a50214ee2b77db6053164ee0f.pdf?index=true'. The presence of a low-severity heuristic for a 'download button' lure further supports the malicious intent. The document body, though heavily obfuscated, contains references to the malicious URL and what appears to be metadata from the wkhtmltopdf tool, suggesting it was generated programmatically to host these links.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=movierulz+ms+sahoo
    • https://bda3d5e3-80c1-45d8-9d73-c46e4bf76222.filesusr.com/ugd/dad7b5_1ea5a27a50214ee2b77db6053164ee0f.pdf?index=true
    • https://ab52f383-94a4-48aa-9001-018fc4ea7f77.filesusr.com/ugd/4c3ae3_1ab22bc6e9b94cc3bf817f2cb05c1776.pdf?index=true
    • https://d0b8dcbc-0824-434f-86d0-75e9b5157a6b.filesusr.com/ugd/51c472_9c3422133b304439b3b2d81c187e1a1e.pdf?index=true
    • https://09b3ca44-f68e-40c2-a62d-5f248063fca9.filesusr.com/ugd/bfd78a_021366761fae4ecbbf42f73355e5a19e.pdf?index=true
    • https://7e442d66-c943-4c4f-a365-72bf125a8685.filesusr.com/ugd/2ca22b_a7fc17ecaf564590b20d66a5346c80b0.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0430/3863/8241/files/fosiwipesakefopame.pdf
    • https://cdn.shopify.com/s/files/1/0430/8680/7201/files/la_boheme_aznavour_sheet_music.pdf
    • https://cdn.shopify.com/s/files/1/0486/2486/1349/files/jixefenuged.pdf
    • https://cdn.shopify.com/s/files/1/0464/8078/5576/files/63101263634.pdf
    • https://cdn.shopify.com/s/files/1/0460/7918/0964/files/coast_guard_assistant_commandant_notification.pdf
    • https://cdn.shopify.com/s/files/1/0459/8648/0295/files/69773579530.pdf
    • https://cdn.shopify.com/s/files/1/0435/1574/0312/files/215895252.pdf
    • https://cdn.shopify.com/s/files/1/0461/9708/0217/files/86970877559.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008016.bin
1b3af3c9c029c9aabad73477792bf17da3ee5df314af577e7ae061b316372e01
pdf-font-stream PDF embedded font (sfnt) at offset 0x8016 5040 bytes
font_01_sfnt_off00009123.bin
8eca31553d111322a773c55c039b533d4121fb65b36f70d3b903e68a00915c1a
pdf-font-stream PDF embedded font (sfnt) at offset 0x9123 15916 bytes
font_02_sfnt_off0000c319.bin
ead7fd593d7f5feef6f283420e9b55f8fa4552f107c64b0063d474dd3355abd8
pdf-font-stream PDF embedded font (sfnt) at offset 0xC319 16164 bytes