Malicious PDF — malware analysis report

Static analysis result for SHA-256 50621f344fdf9885…

MALICIOUS

PDF

44.3 KB Created: 2020-08-30 06:46:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8d6b168057bf57744c30baca2abeb8b4 SHA-1: 39824ff8eabf3df06fe8e3f3e0cf51cd7d22812f SHA-256: 50621f344fdf9885e0d7cd4077f7a854ac16b5a1d6680c79406152351b185bd1
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. Additionally, it exhibits a PDF link farm heuristic, with numerous links to Shopify domains, suggesting an attempt to obscure the final malicious destination. The document body, though heavily obfuscated, contains the malicious URL, reinforcing the redirector finding. The presence of a 'download button' lure further supports a malicious workflow.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=apache+karaf+cookbook+pdf
    • https://cdn.shopify.com/s/files/1/0430/5698/8317/files/56657488221.pdf
    • https://cdn.shopify.com/s/files/1/0436/1479/7981/files/angioedema_hereditario_y_adquirido.pdf
    • https://cdn.shopify.com/s/files/1/0429/6084/7007/files/zusabolomore.pdf
    • https://cdn.shopify.com/s/files/1/0431/1348/0354/files/suvutolinixosuj.pdf
    • https://static.usrfiles.com/ugd/b8c837_7de014100b8241b9abae2cccd0627259.pdf
    • https://static.usrfiles.com/ugd/a6e5e9_b6836aea0da24c68930ab91ac48f120b.pdf
    • https://static.usrfiles.com/ugd/b8c837_4bd0e40eb6e04721a88f651f4d4435b1.pdf
    • https://static.usrfiles.com/ugd/599f1c_78200f423637463d8ac2a01ae93abe3d.pdf
    • https://cdn.shopify.com/s/files/1/0434/3165/7621/files/figoguporipumikuxewalos.pdf
    • https://cdn.shopify.com/s/files/1/0434/2585/7703/files/bimibelibovob.pdf
    • https://cdn.shopify.com/s/files/1/0438/4007/7986/files/classroom_rules_and_expectations_template.pdf
    • https://cdn.shopify.com/s/files/1/0430/3739/3049/files/tatalaksana_acne_vulgaris.pdf
    • https://cdn.shopify.com/s/files/1/0431/3009/3728/files/family_finger_puppet_template.pdf
    • https://cdn.shopify.com/s/files/1/0439/8533/8526/files/latex_subfigure_package.pdf
    • https://cdn.shopify.com/s/files/1/0436/0844/0990/files/tesis_auditoria_ambiental.pdf
    • https://cdn.shopify.com/s/files/1/0431/0417/4233/files/9697231564.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006359.bin
7ef900c8c03f832e69089da052a30528414e98993d88bdd8014d500d5d36b573
pdf-font-stream PDF embedded font (sfnt) at offset 0x6359 4780 bytes
font_01_sfnt_off00007397.bin
9dece19051aeed18a0d3decf679b09de7a977d2f3345e87a3ae183199f4067f0
pdf-font-stream PDF embedded font (sfnt) at offset 0x7397 10192 bytes
font_02_sfnt_off00009676.bin
05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176
pdf-font-stream PDF embedded font (sfnt) at offset 0x9676 4324 bytes