Malicious PDF — malware analysis report

Static analysis result for SHA-256 4a862fb8856f4192…

MALICIOUS

PDF

43.0 KB Created: 2020-08-30 01:43:46 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6a1bb1ebbbf5e054934c55beb428e142 SHA-1: 163146d63eafb63e8e1d347141db606314b557f8 SHA-256: 4a862fb8856f41920ee04bda44d246381e16868a7e20a09964387e92a6dc9f08
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.001 Malicious Link T1059.001 PowerShell

The PDF file contains a large number of embedded links, many of which point to Shopify domains hosting other PDFs, but one critical link directs to a known malicious redirector. This suggests a link farm or SEO poisoning tactic designed to obscure the ultimate malicious destination. The primary malicious URL identified is https://ttraff.com/wix?keyword=los+arcanos+de+thoth, which is flagged as a malicious redirector.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=los+arcanos+de+thoth
    • https://cdn.shopify.com/s/files/1/0428/4016/2470/files/54443012473.pdf
    • https://cdn.shopify.com/s/files/1/0430/6799/8359/files/32228268811.pdf
    • https://cdn.shopify.com/s/files/1/0432/0516/5216/files/fulaxanizenuwed.pdf
    • https://cdn.shopify.com/s/files/1/0432/3196/9438/files/6th_grade_short_reading_comprehension_worksheets.pdf
    • https://cdn.shopify.com/s/files/1/0432/7663/2217/files/23477936239.pdf
    • https://static.usrfiles.com/ugd/a59130_e4cf5b0a78de4f5f8042f49978e16187.pdf
    • https://static.usrfiles.com/ugd/e2f7e1_dda0a95b1fad4429a3f8742c574ec925.pdf
    • https://static.usrfiles.com/ugd/b11f6d_92b1c03c326d4ce2a3c6e5ab4213ea42.pdf
    • https://cdn.shopify.com/s/files/1/0432/3108/4708/files/11138148524.pdf
    • https://cdn.shopify.com/s/files/1/0428/6673/7311/files/piludilatikepet.pdf
    • https://cdn.shopify.com/s/files/1/0435/6908/6619/files/3557915145.pdf
    • https://cdn.shopify.com/s/files/1/0432/2584/1819/files/quartz_crystal_oscillator.pdf
    • https://static.usrfiles.com/ugd/0e2875_0ee55d0f02bb49698da80eda6ec0c81c.pdf
    • https://static.usrfiles.com/ugd/a107db_f2e4c5c079eb440fae093a36ab7a11f3.pdf
    • https://static.usrfiles.com/ugd/de65f7_a2b07828b2674b83b1937ce943a4aa13.pdf
    • https://static.usrfiles.com/ugd/51c472_610b101382d54f1eb9b583d12bc5c0f7.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000693c.bin
3b3bfbd590a3e14aad57fecaa6a67fcd5f8a4bb93298921c7b5de8e02dd52f12
pdf-font-stream PDF embedded font (sfnt) at offset 0x693C 4936 bytes
font_01_sfnt_off000079f2.bin
57d56530037b0535a45fec1aa3fd0de517e372bdfc1f5f08d053e0d6749658b1
pdf-font-stream PDF embedded font (sfnt) at offset 0x79F2 11032 bytes