Malicious PDF — malware analysis report

Static analysis result for SHA-256 93902a4854e3a867…

MALICIOUS

PDF

68.2 KB Created: 2020-09-02 00:04:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 364270c900e66cad86d1275fc88ac150 SHA-1: 1eb3868398cfa577a170c7592c9ba19040aee3ea SHA-256: 93902a4854e3a867703cd0d95f8a3ebe03e0c7026200e17d883c9635a1e5d76b
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link and a social engineering lure to install a browser extension. The embedded URL points to 'ttraff.com', which is flagged as malicious. The document body, though heavily obfuscated, contains this URL, suggesting it's the primary lure. The PDF also contains a large number of external links, potentially for SEO manipulation or to distribute further malicious content.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=bootstrap+form+error+color
    • https://cdn.shopify.com/s/files/1/0440/5441/3462/files/milady_chapter_5_theory_workbook_answers.pdf
    • https://cdn.shopify.com/s/files/1/0440/4684/4054/files/23577850545.pdf
    • https://cdn.shopify.com/s/files/1/0433/2378/5370/files/chuyn_i_nh_jpg_sang.pdf
    • https://static.usrfiles.com/ugd/5cd33b_178709a197d14a5aa9c9bd304fdf5f77.pdf
    • https://static.usrfiles.com/ugd/99b222_8055cac24f424aa9aea74e65df5bb2d6.pdf
    • https://static.usrfiles.com/ugd/b4609a_0c6a70e606fb4655b40bdbbe928876d5.pdf
    • https://static.usrfiles.com/ugd/1479de_728a7d359c1945299d9125e5604a9036.pdf
    • https://static.usrfiles.com/ugd/3e9e83_9fd6db5f4f3e4d7f8e1c683fabb207fb.pdf
    • https://static.usrfiles.com/ugd/529ba0_77839414727944a89eb7b9e592265cd0.pdf
    • https://cdn.shopify.com/s/files/1/0430/4565/0586/files/sailing_to_byzantium_symbolism.pdf
    • https://cdn.shopify.com/s/files/1/0440/0149/3142/files/36420048024.pdf
    • https://cdn.shopify.com/s/files/1/0439/5555/2414/files/zudemenewepejoxevogigaf.pdf
    • https://cdn.shopify.com/s/files/1/0431/2878/3002/files/jofoxupisumewerutoni.pdf
    • https://cdn.shopify.com/s/files/1/0434/2795/4840/files/37672858183.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000bdc0.bin
78ed86fe15c7e7a6905f61766b1d7274ec8ffa043447285914995abc75c11a06
pdf-font-stream PDF embedded font (sfnt) at offset 0xBDC0 5212 bytes
font_01_sfnt_off0000cf69.bin
a0c05fd92891e4d55f1897d4e7ad131a79ab30461d1afe9680c1617c4d5a1a3e
pdf-font-stream PDF embedded font (sfnt) at offset 0xCF69 16972 bytes