Malicious PDF — malware analysis report

Static analysis result for SHA-256 7d62a3b04fe0c944…

MALICIOUS

PDF

46.7 KB Created: 2020-08-19 23:50:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6e9d211ccbb8befa3256a70f2af05526 SHA-1: 97de5a908878fc288346c45933959d6dc46bdec6 SHA-256: 7d62a3b04fe0c944b95155df354660e42b933bc2b1cdfab08bfc1fc118ca76bc
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing indicating it links to a known malicious redirector, ttraff.com. The document body, though heavily obfuscated, contains the same URL, suggesting the primary intent is to redirect the user to malicious infrastructure. The presence of numerous other links to Shopify-hosted PDFs suggests a link farm or SEO poisoning tactic to increase the visibility of the malicious redirector.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=biomedical+importance+of+carbohydrates+pdf
    • http://files.thepygmygoatclubofireland.com/uploads/1/3/1/3/131383444/xusoguw.pdf
    • http://forumox.herbesque.com/uploads/1/3/1/6/131637136/6716099.pdf
    • https://cdn.shopify.com/s/files/1/0433/1234/9334/files/kibirurodazitafaminawujin.pdf
    • https://cdn.shopify.com/s/files/1/0435/8553/6159/files/discrete_probability_distribution_exercises.pdf
    • https://cdn.shopify.com/s/files/1/0437/7506/6273/files/28453838141.pdf
    • https://cdn.shopify.com/s/files/1/0432/2020/5726/files/popovasor.pdf
    • https://cdn.shopify.com/s/files/1/0434/5892/0605/files/81984861381.pdf
    • https://cdn.shopify.com/s/files/1/0428/7250/4483/files/66229403094.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/97428896976.pdf
    • https://cdn.shopify.com/s/files/1/0428/1548/8163/files/jazijudovojalowulisigabuf.pdf
    • https://cdn.shopify.com/s/files/1/0433/7827/8550/files/24597735770.pdf
    • https://cdn.shopify.com/s/files/1/0435/8645/3663/files/advanced_systemcare_pro_9_key.pdf
    • https://cdn.shopify.com/s/files/1/0431/5840/5275/files/dubaxodirojarerokulib.pdf
    • https://cdn.shopify.com/s/files/1/0434/1337/3084/files/alleluia_marcelo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006eb1.bin
4d3fb6748bdbfc0676bbc246a341b567ec3707c335db72ae26270b639488ab50
pdf-font-stream PDF embedded font (sfnt) at offset 0x6EB1 1684 bytes
font_01_sfnt_off00007715.bin
231e389cb85137ac4da15b4e31f26e27983bb86166e1feb2636d614cb2319d35
pdf-font-stream PDF embedded font (sfnt) at offset 0x7715 5688 bytes
font_02_sfnt_off00008a35.bin
5590560d963fca4198bde7eb9d53e1692c3cba274c6a9b9cc1dd4df14c1c2316
pdf-font-stream PDF embedded font (sfnt) at offset 0x8A35 10284 bytes