Malicious PDF — malware analysis report

Static analysis result for SHA-256 97a40d850e989ba3…

MALICIOUS

PDF

45.6 KB Created: 2020-08-31 23:41:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8e443216132ea9c0a1934f77c5d12216 SHA-1: fda232592685817022fd92c05eeef59f2e99feaa SHA-256: 97a40d850e989ba38179475f0dddc8c4cd5814fc4c884b2cd459d5960da37021
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.com/wix?keyword=java+8+msi+offline+installer'. This URL is likely part of a phishing or malware distribution scheme, attempting to trick users into downloading malicious software by disguising the link as a legitimate installer. The document body, though heavily corrupted, also contains this URL, reinforcing its role as the primary lure.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=java+8+msi+offline+installer
    • https://cdn.shopify.com/s/files/1/0429/2175/4787/files/56975227921.pdf
    • https://cdn.shopify.com/s/files/1/0428/1057/2967/files/cursive_bed_sheets.pdf
    • https://cdn.shopify.com/s/files/1/0431/4667/4336/files/diabetic_dyslipidemia.pdf
    • https://cdn.shopify.com/s/files/1/0437/1320/0278/files/dikizaserirowoxi.pdf
    • https://static.usrfiles.com/ugd/f4de5e_03629aaba9c74ed9b818020f4d4251bd.pdf
    • https://static.usrfiles.com/ugd/906e9f_8bdde8d1e43c405081cae9ef1cf37629.pdf
    • https://static.usrfiles.com/ugd/b8c837_6f53ec0b69594ddd80c7ee7099861fe4.pdf
    • https://static.usrfiles.com/ugd/de3d83_135411abbc14408e8ccd5d1634bd38f6.pdf
    • https://static.usrfiles.com/ugd/5cf23b_59ffca9c98214a04b608442377fbbff5.pdf
    • https://static.usrfiles.com/ugd/95089d_d603b146536d40a8bd796fc383dcda7b.pdf
    • https://static.usrfiles.com/ugd/3826db_2dd59fb977744a3385632f8f7ddf94cf.pdf
    • https://static.usrfiles.com/ugd/10e3af_c0098f490ad3447bbdde3995ec10be9a.pdf
    • https://static.usrfiles.com/ugd/b8c837_2f6107fba7ee425ba769464669ef6d58.pdf
    • https://static.usrfiles.com/ugd/b8c837_95e3fd9b63754def9f9f155dcc2c4c7c.pdf
    • https://static.usrfiles.com/ugd/ef7b09_2965174643664e25b05861fbfc346a86.pdf
    • https://static.usrfiles.com/ugd/909b15_8ea56548d634464fa1222ce14a6bf20e.pdf
    • https://static.usrfiles.com/ugd/5360f8_27205eb04fa64a7cbb87d2c94d1a44e7.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000669d.bin
0e3b8cf7632fa5268c1f334b39a8d920f22ae1c790c80e1d80c79c7e8b6d23e0
pdf-font-stream PDF embedded font (sfnt) at offset 0x669D 4944 bytes
font_01_sfnt_off0000774c.bin
14f8890cbeb53f20237325c769ca50c5a84b0aa64c8f5b044eda8781efdc8c20
pdf-font-stream PDF embedded font (sfnt) at offset 0x774C 10612 bytes
font_02_sfnt_off00009b51.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0x9B51 4324 bytes