Malicious PDF — malware analysis report

Static analysis result for SHA-256 8110b8a60c744235…

MALICIOUS

PDF

66.8 KB Created: 2020-08-22 05:55:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 86a3afdf95115bd1f2366943e94f9206 SHA-1: fa7782aae8b3e02e5034da0c763957962f6aaba0 SHA-256: 8110b8a60c744235c3aa9ed680b2aec05e096b59ab90c3aefc434488e68e5a63
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a significant number of embedded links, many pointing to Shopify domains, forming a link farm. One critical heuristic indicates a PDF redirector link to 'ttraff.com', which is known malicious infrastructure. The document body, though heavily obfuscated, also contains this URL. This suggests the PDF is designed to lure users into clicking malicious links, likely for phishing or to download further malware.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=kathi+mela+kathi+song++masstamilan.+org
    • http://files.prorigdept.com/uploads/1/3/1/6/131637881/6523490.pdf
    • https://cdn.shopify.com/s/files/1/0434/8385/7053/files/kiwepigegevoviwekas.pdf
    • https://cdn.shopify.com/s/files/1/0433/6612/1623/files/pvc_foam_sheet_manufacturers_in_china.pdf
    • https://cdn.shopify.com/s/files/1/0448/3714/2690/files/cell_division_mitosis_and_meiosis_answer_key.pdf
    • https://cdn.shopify.com/s/files/1/0428/6464/0159/files/fosazisajiz.pdf
    • https://cdn.shopify.com/s/files/1/0428/2390/9532/files/kabikivabosugemijotej.pdf
    • https://cdn.shopify.com/s/files/1/0435/0889/1807/files/tinivarajek.pdf
    • https://cdn.shopify.com/s/files/1/0436/9380/1625/files/45955009008.pdf
    • https://cdn.shopify.com/s/files/1/0434/7160/1817/files/factores_biologicos_definicion.pdf
    • https://cdn.shopify.com/s/files/1/0430/9696/5269/files/45885185404.pdf
    • https://cdn.shopify.com/s/files/1/0432/0913/0143/files/articles_dfinis_indfinis_partitifs_contracts_exercices_corrigs.pdf
    • https://cdn.shopify.com/s/files/1/0448/8462/3527/files/habanera_carmen_bizet.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007eeb.bin
efa23be824acca3f0284f758a18006352b9936f4efead95d145598daa2e784ba
pdf-font-stream PDF embedded font (sfnt) at offset 0x7EEB 5164 bytes
font_01_sfnt_off00009052.bin
c512ed0bf5ba20d056eb2a05a70077ee0d6b72f1b411ac1f97c5bdfae6dc391e
pdf-font-stream PDF embedded font (sfnt) at offset 0x9052 4936 bytes
font_02_sfnt_off0000a12d.bin
7e32589233d0f03e126d460e1e035a17c9d3d06c79dd444d1bfe01a96e5fd151
pdf-font-stream PDF embedded font (sfnt) at offset 0xA12D 3004 bytes
font_03_sfnt_off0000ac9d.bin
f855d6158e8f916bd7c297b857e55ede5ab5e187a93aa334f78670c586761fb3
pdf-font-stream PDF embedded font (sfnt) at offset 0xAC9D 15752 bytes
font_04_sfnt_off0000dd5c.bin
1df41416ece054d3cca32f135e48dc95f4d9c8a2bff4ba4edba1d14e21aabef6
pdf-font-stream PDF embedded font (sfnt) at offset 0xDD5C 18776 bytes