Malicious PDF — malware analysis report

Static analysis result for SHA-256 7d5d3d87345ee21c…

MALICIOUS

PDF

35.5 KB Created: 2020-08-20 09:32:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 470197d24c64a2a3d4eea55099342032 SHA-1: 2a1aaadbaba6f49dabdf8ad8cd034765a7ea1a05 SHA-256: 7d5d3d87345ee21cd9d4c06c30b3fa8e1b2237b1bc2da40dcf1f1a78207ab266
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, many of which point to Shopify domains hosting other PDFs, suggesting a link farm or SEO poisoning tactic. One critical heuristic firing indicates a direct link to a known malicious redirector, ttraff.com, which is used to obscure the final malicious destination. The document body itself contains garbled text but also includes the malicious redirector URL and several Shopify URLs, reinforcing the lure. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=art+of+problem+solving+pdf
    • http://files.arteristrutturare.com/uploads/1/3/0/9/130969705/kifatodojibuvuji.pdf
    • http://punesejo.torilaynepermanentcosmetics.net/uploads/1/3/2/7/132712354/78eb935142cd2.pdf
    • https://cdn.shopify.com/s/files/1/0437/7663/9127/files/chuuka_ichiban_sub_indo_batch.pdf
    • https://cdn.shopify.com/s/files/1/0436/5480/7717/files/vukafuraxufawodaguv.pdf
    • https://cdn.shopify.com/s/files/1/0429/0668/1497/files/73913067840.pdf
    • https://cdn.shopify.com/s/files/1/0427/8072/1311/files/85881664479.pdf
    • https://cdn.shopify.com/s/files/1/0431/5794/6519/files/50342397420.pdf
    • https://cdn.shopify.com/s/files/1/0434/8693/7253/files/jetefemo.pdf
    • https://cdn.shopify.com/s/files/1/0428/9187/0375/files/jepefigugalawuboba.pdf
    • https://cdn.shopify.com/s/files/1/0430/9339/3557/files/xanamitefigid.pdf
    • https://cdn.shopify.com/s/files/1/0432/3786/7680/files/37548403050.pdf
    • https://cdn.shopify.com/s/files/1/0431/7783/6702/files/33352584609.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004e34.bin
f2961e9e6d63aec38cdd9678f437da900b0cc5831ab5e76996644286bacf6b79
pdf-font-stream PDF embedded font (sfnt) at offset 0x4E34 5340 bytes
font_01_sfnt_off0000604a.bin
ce08c7dcefed215234cf229f268524e324549bb6134b0bc5781c5ff850a7c387
pdf-font-stream PDF embedded font (sfnt) at offset 0x604A 9756 bytes