Malicious PDF — malware analysis report

Static analysis result for SHA-256 7bfb131b8a06ca1e…

MALICIOUS

PDF

70.4 KB Created: 2020-07-27 01:52:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c2afba7ca410cdf047299c0977bd623f SHA-1: a047cdffe957f28f33dedcc28f3d1d3860060d6f SHA-256: 7bfb131b8a06ca1e97811c2e25bfb6f15bea30518e30adb36ed33f7ca7b4683b
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. Additionally, it exhibits a PDF link farm heuristic, with numerous links hosted on 'cdn.shopify.com', suggesting an attempt to distribute content or lure users. The document body, though heavily obfuscated, contains metadata related to 'wkhtmltopdf' and a date, but no clear textual lure. The primary attack vector appears to be the malicious redirector.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=amnesia+memories+ost
    • http://files.stmatthewsworcester.org/uploads/1/3/0/7/130738755/365348.pdf
    • http://files.nycmetrostars.com/uploads/1/3/0/7/130776073/4bd8c.pdf
    • http://files.curvycreoleroux.com/uploads/1/3/1/4/131407067/wulam.pdf
    • http://files.whimsicalsragdoll.com/uploads/1/3/0/8/130814680/1e079.pdf
    • https://cdn.shopify.com/s/files/1/0436/3078/8758/files/23422066838.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/90442425312.pdf
    • https://cdn.shopify.com/s/files/1/0439/0171/4587/files/fazisorudenaposib.pdf
    • https://cdn.shopify.com/s/files/1/0436/8682/2053/files/levususebok.pdf
    • https://cdn.shopify.com/s/files/1/0432/1899/3307/files/6481338984.pdf
    • https://cdn.shopify.com/s/files/1/0433/9141/8526/files/66492837338.pdf
    • https://cdn.shopify.com/s/files/1/0434/9041/0658/files/xadunaxugogiramek.pdf
    • https://cdn.shopify.com/s/files/1/0428/3128/2335/files/19932723025.pdf
    • https://cdn.shopify.com/s/files/1/0433/9345/0134/files/96425256357.pdf
    • https://cdn.shopify.com/s/files/1/0440/6879/8614/files/lawetikojiwefipisezekivu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000c357.bin
48b7abb445dc131d430bf0de4ac3064d544bfb4332a1133d49c79460cd10bd50
pdf-font-stream PDF embedded font (sfnt) at offset 0xC357 6080 bytes
font_01_sfnt_off0000d823.bin
337e5d4d9307de371eafab9cc759cfd1c5ea86d33116dd8369998424e9227bbb
pdf-font-stream PDF embedded font (sfnt) at offset 0xD823 4576 bytes
font_02_sfnt_off0000e77b.bin
aeb2dc8a30e8898619181531c7e11faa916b2d3095dfa54ba095cded8af17ebf
pdf-font-stream PDF embedded font (sfnt) at offset 0xE77B 10140 bytes