Malicious PDF — malware analysis report

Static analysis result for SHA-256 52d10245d729ecb8…

MALICIOUS

PDF

56.8 KB Created: 2020-08-27 13:05:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7d1c4d5db978d39ade8ce04015b62faa SHA-1: 1e5992512d8596e7e071dba1dd61218852e18f79 SHA-256: 52d10245d729ecb8f05a08b9423f0fb1a41e1bbcf59470395666ce4d915c2a27
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://ttraff.com/pify?keyword=download+marvel+endgame'. Additionally, it exhibits a PDF link farm heuristic, indicating a large number of external links, many hosted on Shopify. The document body, though heavily obfuscated, contains the same malicious URL and references to downloading content, reinforcing the lure. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=download+marvel+endgame
    • http://files.shannonlarsen.com/uploads/1/3/1/4/131453329/dexabotawirekobix.pdf
    • http://kingmovies.us/movie/299534/avengers-e
    • https://cdn.shopify.com/s/files/1/0430/3942/4669/files/84490423747.pdf
    • https://cdn.shopify.com/s/files/1/0432/9416/3109/files/jurnal_hematology_analyzer.pdf
    • https://cdn.shopify.com/s/files/1/0431/1754/3588/files/ludarajoxotutavufixo.pdf
    • https://cdn.shopify.com/s/files/1/0429/5327/7589/files/93794603742.pdf
    • https://cdn.shopify.com/s/files/1/0436/5464/3877/files/vebumeze.pdf
    • https://cdn.shopify.com/s/files/1/0437/7106/8577/files/58612567359.pdf
    • https://cdn.shopify.com/s/files/1/0433/1149/7366/files/jpg_to_word_converter_i_love.pdf
    • https://cdn.shopify.com/s/files/1/0428/6529/5526/files/gofusepozim.pdf
    • https://cdn.shopify.com/s/files/1/0436/9340/8409/files/tuxatixizotuxera.pdf
    • https://cdn.shopify.com/s/files/1/0454/3139/0364/files/18491274492.pdf
    • https://cdn.shopify.com/s/files/1/0431/1603/6257/files/6th_grade_staar_math_practice_worksheets.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off00008100.bin
26178d49e0a7dd52d0d87fdc754063bfdf3474723f677a3305898ad2a796cefa
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8100 12912 bytes
font_00_sfnt_off0000545a.bin
048fb1891f432488516cd811e7b04d68e7d39e548ca3495625137f8fb0c23ff4
pdf-font-stream PDF embedded font (sfnt) at offset 0x545A 6744 bytes
font_01_sfnt_off0000650e.bin
e211f2d6e0d1bf1fd17bd5150bc2724fb7c0f1d37b1c69b855d9dcad8de34ab0
pdf-font-stream PDF embedded font (sfnt) at offset 0x650E 2952 bytes
font_02_sfnt_off00006f9c.bin
98234e5cb33b2eaa51373573191b4904041359a120a841758e80b288c27d19c6
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F9C 5120 bytes
font_04_sfnt_off0000a5d6.bin
a1c68180eae955d710b1f59d89b7b5bb1f22246194deffa7b9c3298859733f9b
pdf-font-stream PDF embedded font (sfnt) at offset 0xA5D6 2140 bytes
font_05_sfnt_off0000afae.bin
038ffd54f26b503cfb89a04b07380fbd346339be2fa4dd43f44a9ec6d04d4da8
pdf-font-stream PDF embedded font (sfnt) at offset 0xAFAE 10908 bytes