Malicious PDF — malware analysis report

Static analysis result for SHA-256 4ca0de6f4b824d21…

MALICIOUS

PDF

66.5 KB Created: 2020-09-01 03:49:41 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 274b55247879752e9611b99d4920a0ba SHA-1: a85af1b780f7973191c2170d15d80b5d4dc104c3 SHA-256: 4ca0de6f4b824d215bb107404e041c5238c28d8f5ab10c3cbd2029cbca077313
130 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.cc/wix?keyword=social+anxiety+treatment+worksheets'. Additionally, it exhibits characteristics of a PDF link farm, with numerous external links, many hosted on static.usrfiles.com. The document body, though heavily obfuscated, contains the same URL, suggesting a lure to a malicious site under the guise of providing worksheets.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=social+anxiety+treatment+worksheets
    • https://cdn.shopify.com/s/files/1/0431/6453/2900/files/pdf_to_word_file_converter_online_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0440/4386/2181/files/37220068596.pdf
    • https://cdn.shopify.com/s/files/1/0436/5467/6645/files/gifuk.pdf
    • https://cdn.shopify.com/s/files/1/0435/3084/6363/files/bristleback_item_guide_dota_2.pdf
    • https://static.usrfiles.com/ugd/314c35_eac62176a4264f4eaf050ef5da251490.pdf
    • https://static.usrfiles.com/ugd/05900a_1aa895a05e6c41c483943a1ae056803e.pdf
    • https://static.usrfiles.com/ugd/b8c837_6b6aa1f6836a47dfb7b7df5241736d61.pdf
    • https://static.usrfiles.com/ugd/1be480_b01b214f1ff841af8bb01ca659466b0b.pdf
    • https://static.usrfiles.com/ugd/7e6083_c70b6b183c254c5b829a7fbcc8b26ca4.pdf
    • https://static.usrfiles.com/ugd/b8c837_b69608f8a6cb4ba3a53679ceec1af1fc.pdf
    • https://static.usrfiles.com/ugd/97493d_dc33f63ab33a484997d506ad860bce6a.pdf
    • https://static.usrfiles.com/ugd/a4e402_07db749560fe4bb9948afa1b34219e45.pdf
    • https://static.usrfiles.com/ugd/4b7290_96eb577b07b949fc86c7046ef5d5d2a3.pdf
    • https://static.usrfiles.com/ugd/eb6612_703be77e0e41480eb51e2d851d927a7f.pdf
    • https://static.usrfiles.com/ugd/e2c250_36ad07cec23743d9a39041e8b93c45ba.pdf
    • https://static.usrfiles.com/ugd/b8c837_b15d50d21fc74e01b4827209e2ba98de.pdf
    • https://static.usrfiles.com/ugd/b916f4_c4addc0757fe47919437d3e9b2f1fe4c.pdf
    • https://static.usrfiles.com/ugd/2486b5_ec66a0a30cd64a739a8eec79e329c15e.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com/s/files/1/0440/4

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c656.bin
abbc8f85f892a64927f259867edc0786075b600c0a29004e35becadd1a30d4b1
pdf-font-stream PDF embedded font (sfnt) at offset 0xC656 5468 bytes
font_01_sfnt_off0000d8e1.bin
af0c86110de0f3e34e3bbe834f7510f1b1ecc627fde3d04ca414b583298c32dc
pdf-font-stream PDF embedded font (sfnt) at offset 0xD8E1 10624 bytes