Malicious PDF — malware analysis report

Static analysis result for SHA-256 5122e5b101655bd5…

MALICIOUS

PDF

38.8 KB Created: 2020-08-30 12:32:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 50dc39f1fff3ef5dccd6df02fbc4ea71 SHA-1: a3076060cf8c3559ba46f323db91b55c3f2d84bc SHA-256: 5122e5b101655bd5cea60b82460b903a733596cc7a0110ded07da18ed15f567b
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains embedded JavaScript and multiple external links, one of which, 'https://ttraff.me/wix?keyword=enrique+iglesias+hero.mp3', is flagged as a malicious redirector. The document body also contains this URL and a list of other Shopify-hosted PDF links, suggesting a link farm or redirection tactic. The presence of embedded JavaScript and the malicious redirector link indicate an attempt to lead the user to malicious content, likely for phishing or malware delivery.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=enrique+iglesias+hero.mp3
    • https://cdn.shopify.com/s/files/1/0435/4467/4455/files/14009111350.pdf
    • https://cdn.shopify.com/s/files/1/0435/5152/2977/files/haku_spirited_away_dragon.pdf
    • https://cdn.shopify.com/s/files/1/0439/5224/2856/files/nixigudijenopijemexofil.pdf
    • https://cdn.shopify.com/s/files/1/0431/0574/7108/files/33105451924.pdf
    • https://cdn.shopify.com/s/files/1/0430/9496/6436/files/www_myalconlensrebates_com_form.pdf
    • https://cdn.shopify.com/s/files/1/0428/8679/1334/files/java_break_out_of_for_loop.pdf
    • https://cdn.shopify.com/s/files/1/0430/3765/5191/files/honda_manual_transmission_fluid.pdf
    • https://cdn.shopify.com/s/files/1/0439/8769/7822/files/wolidozezebe.pdf
    • https://cdn.shopify.com/s/files/1/0437/4305/1937/files/18947892224.pdf
    • https://cdn.shopify.com/s/files/1/0428/2823/4908/files/78205192239.pdf
    • https://cdn.shopify.com/s/files/1/0430/4008/0023/files/grasshopper_mower_parts.pdf
    • https://cdn.shopify.com/s/files/1/0430/9581/8404/files/warajekukuj.pdf
    • https://cdn.shopify.com/s/files/1/0431/7180/7392/files/antidiabetic_drugs_review.pdf
    • https://cdn.shopify.com/s/files/1/0440/1355/1781/files/10316303709.pdf
    • https://cdn.shopify.com/s/files/1/0430/7098/0245/files/52567452728.pdf
    • https://cdn.shopify.com/s/files/1/0432/8102/3132/files/9484859902.pdf
    • https://cdn.shopify.com/s/files/1/0437/1300/3674/files/interrogative_sentence_definition.pdf
    • https://cdn.shopify.com/s/files/1/0432/0159/3502/files/gibaxevanaje.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004af4.bin
2028fea8032bf95a3dbbbcc93e96d9b44ae4cba19d21a5124d6d38b93e5d12da
pdf-font-stream PDF embedded font (sfnt) at offset 0x4AF4 5312 bytes
font_01_sfnt_off00005ccc.bin
565feff40c60fb7851b1bdf2cb1806acd62db2a00ac1e2832567f1525f4797cf
pdf-font-stream PDF embedded font (sfnt) at offset 0x5CCC 10500 bytes
font_02_sfnt_off00007fec.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0x7FEC 4324 bytes