Malicious PDF — malware analysis report

Static analysis result for SHA-256 92e4d89355ce9bc3…

MALICIOUS

PDF

54.5 KB Created: 2020-08-17 10:42:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6f5a313953f64bef0c5c49575cb083bc SHA-1: db719aec89a3148028267d3dcc9ff7c851c6d4d8 SHA-256: 92e4d89355ce9bc38742b48eb73def5b344b68051f962eeca567d6abd294ad20
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged for containing a malicious redirector link and a large number of external links, suggesting a link farm. The primary malicious URL identified is ttraff.cc, which is known for redirecting to malicious sites. The document body contains garbled text but also includes the malicious URL and several other URLs, some of which are benign Shopify links and others are unknown. The presence of a malicious redirector link strongly indicates a phishing or malware distribution attempt.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=peter+jackson%2527+s+king+kong+pc+demo
    • http://files.mosaicfamilyinc.com/uploads/1/3/0/7/130775046/5081444.pdf
    • http://files.artartmargaretcameron.com/uploads/1/3/1/3/131381450/lazolinegasefu.pdf
    • http://files.wonderfulpowerfulme.com/uploads/1/3/1/8/131871721/03ba0e507f69b.pdf
    • http://jijinidog.jamesawatsonjr.net/uploads/1/3/0/8/130813765/8237951.pdf
    • https://cdn.shopify.com/s/files/1/0431/5627/5362/files/biogas_plant_model.pdf
    • https://cdn.shopify.com/s/files/1/0433/6936/5654/files/kenmore_front_load_washer_manual.pdf
    • https://cdn.shopify.com/s/files/1/0431/2363/8426/files/44469558878.pdf
    • https://cdn.shopify.com/s/files/1/0431/1403/7397/files/belajijasizote.pdf
    • https://cdn.shopify.com/s/files/1/0431/3723/7146/files/4132961113.pdf
    • https://cdn.shopify.com/s/files/1/0430/7389/6602/files/pozilelobuto.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/53975554289.pdf
    • https://cdn.shopify.com/s/files/1/0438/9886/3784/files/8th_grade_social_studies_textbook_mcgraw_hill.pdf
    • https://cdn.shopify.com/s/files/1/0433/5435/7915/files/biografi_syekh_abdul_qodir_jaelani.pdf
    • https://cdn.shopify.com/s/files/1/0432/0470/6464/files/vapopekufunez.pdf
    • https://cdn.shopify.com/s/files/1/0432/6768/6556/files/93178682042.pdf
    • https://cdn.shopify.com/s/files/1/0432/2567/7982/files/78975783969.pdf
    • https://cdn.shopify.com/s/files/1/0434/6498/2693/files/polelufuwigivifakobotegaz.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000620f.bin
982e44a29cb4cb65f6baba8a90ab0c7a4c037374481606b9079c72af03191e45
pdf-font-stream PDF embedded font (sfnt) at offset 0x620F 5324 bytes
font_01_sfnt_off0000740f.bin
aeecc852e023076d737bcf32ce2ef5393b2b2f29a2bc4cad842200493646d9a3
pdf-font-stream PDF embedded font (sfnt) at offset 0x740F 9052 bytes
font_02_sfnt_off00008da1.bin
cd75415a567a228c465daf7250677b8cce0b7e28833c5098d1fb43ed11e78242
pdf-font-stream PDF embedded font (sfnt) at offset 0x8DA1 14604 bytes
font_03_sfnt_off0000bc13.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0xBC13 4324 bytes