Malicious PDF — malware analysis report

Static analysis result for SHA-256 4f19b76e0cce8b10…

MALICIOUS

PDF

45.5 KB Created: 2020-09-02 03:05:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a49d9d45b866569f5014cc7ecac9d921 SHA-1: e97d41b2e06014176cf6613959116ac034858f22 SHA-256: 4f19b76e0cce8b1008b3db3477e3d89b37a58d8ac4eafe479dac0a9f0a0570e6
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a high number of embedded links, many of which point to a link farm hosted on cdn.shopify.com. One critical heuristic indicates a PDF redirector link to 'ttraff.cc', which is known malicious infrastructure. The document body, though heavily obfuscated, contains text related to 'google calendar sync problems android' and includes the malicious URL, suggesting a lure to trick users into clicking. The presence of a 'SE_DOWNLOAD_BUTTON' heuristic further supports the deceptive nature of the document.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=google+calendar+sync+problems+android
    • https://cdn.shopify.com/s/files/1/0428/0870/5187/files/gixutewewafu.pdf
    • https://cdn.shopify.com/s/files/1/0435/5915/7921/files/kuruxulovipivelidiwokumoj.pdf
    • https://cdn.shopify.com/s/files/1/0460/2255/7855/files/hard_drive_regenerator_2011_serial.pdf
    • https://cdn.shopify.com/s/files/1/0436/2846/2233/files/pe_design_10_crack.pdf
    • https://cdn.shopify.com/s/files/1/0435/4827/8935/files/12853689082.pdf
    • https://static.usrfiles.com/ugd/f09a9d_43f18c14f60849d180051903e5b10075.pdf
    • https://static.usrfiles.com/ugd/384ea4_c06c49c3ccc64f5c9149f2ba074181d4.pdf
    • https://static.usrfiles.com/ugd/9ea9b6_33af41465a1244378ad242ba992d8769.pdf
    • https://cdn.shopify.com/s/files/1/0433/5727/4270/files/59129116393.pdf
    • https://cdn.shopify.com/s/files/1/0461/0647/6707/files/faxidedekosojar.pdf
    • https://cdn.shopify.com/s/files/1/0436/0133/0339/files/71633204575.pdf
    • https://cdn.shopify.com/s/files/1/0436/9947/0486/files/52999174598.pdf
    • https://cdn.shopify.com/s/files/1/0427/7737/8972/files/zofovopuramura.pdf
    • https://cdn.shopify.com/s/files/1/0430/2903/7219/files/46302149333.pdf
    • https://cdn.shopify.com/s/files/1/0428/7122/6534/files/97579246865.pdf
    • https://cdn.shopify.com/s/files/1/0433/5825/7306/files/23209419982.pdf
    • https://cdn.shopify.com/s/files/1/0429/9243/5359/files/43589182061.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000722a.bin
f195e753bdc860fa11e04227259dd1a68bbbf70dfa4807a58c177bd79c3b52a3
pdf-font-stream PDF embedded font (sfnt) at offset 0x722A 5664 bytes
font_01_sfnt_off00008561.bin
b1e13157e1dfad7e816339174229c5fb563fbfd62b7b7dbc994b7532b1b7cbd8
pdf-font-stream PDF embedded font (sfnt) at offset 0x8561 10388 bytes