Malicious PDF — malware analysis report

Static analysis result for SHA-256 7c8bd03074de633c…

MALICIOUS

PDF

53.7 KB Created: 2020-08-10 12:12:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 65cbdc2e5fef436353f1729ffcfde86d SHA-1: 273c42307db5850c18183e0fc46eecfbf3476c02 SHA-256: 7c8bd03074de633c38df2bf25ed8d7068e719c6ac1b4b2473b502897f671b0e7
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link pointing to 'ttraff.com'. Additionally, it exhibits characteristics of a PDF SEO link farm, with numerous external links, many hosted on Shopify. The document body, though heavily obfuscated, contains the same malicious URL. The primary attack pattern involves luring the user to click on a link that leads to malicious infrastructure.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=cartesian+robot+design+pdf
    • http://files.missflowersclassroom.com/uploads/1/3/1/6/131636903/9821875.pdf
    • http://files.abideinhiminc.org/uploads/1/3/1/4/131410952/a4021756015cde.pdf
    • http://files.becauseiamawoman.net/uploads/1/3/0/7/130739060/totamam.pdf
    • http://files.bevmcclellanrobynfear.com/uploads/1/3/0/8/130874067/9588005.pdf
    • https://cdn.shopify.com/s/files/1/0435/9946/2558/files/apprendre_l_criture_arabe.pdf
    • https://cdn.shopify.com/s/files/1/0435/2675/0357/files/play_david_banner.pdf
    • https://cdn.shopify.com/s/files/1/0438/2906/7933/files/52062160031.pdf
    • https://cdn.shopify.com/s/files/1/0431/1321/8210/files/72292499054.pdf
    • https://cdn.shopify.com/s/files/1/0433/4272/5275/files/fufufur.pdf
    • https://cdn.shopify.com/s/files/1/0428/2505/6412/files/basic_electronics_components_checking.pdf
    • https://cdn.shopify.com/s/files/1/0428/2250/0518/files/dagikugetigenagejaw.pdf
    • https://cdn.shopify.com/s/files/1/0430/8166/2628/files/vajimoson.pdf
    • https://cdn.shopify.com/s/files/1/0428/9508/1625/files/65147041470.pdf
    • https://cdn.shopify.com/s/files/1/0430/7917/2257/files/77747546602.pdf
    • https://cdn.shopify.com/s/files/1/0432/3796/5986/files/49194587957.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/25781613666.pdf
    • https://cdn.shopify.com/s/files/1/0447/7383/4901/files/5437968523.pdf
    • https://cdn.shopify.com/s/files/1/0428/5366/2883/files/92614590327.pdf
    • https://cdn.shopify.com/s/files/1/0432/8649/5396/files/gejunajaxenuser.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off0000aeb4.bin
c1d307ec0aff0585565f601cea6540c7652ef72374a150bf29add506f73cafc7
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xAEB4 17524 bytes
font_00_sfnt_off000079d0.bin
6e234b749c070da9883f9be14b3cf8137de025ebed94f685661961a6823ec35b
pdf-font-stream PDF embedded font (sfnt) at offset 0x79D0 5220 bytes
font_01_sfnt_off00008b97.bin
7ab6a68e4b1fdc3d44c615abee3a01e45e187bb80f5732157c29b38dd9feba54
pdf-font-stream PDF embedded font (sfnt) at offset 0x8B97 10228 bytes