Malicious PDF — malware analysis report

Static analysis result for SHA-256 97b3b84cc95b8e96…

MALICIOUS

PDF

52.5 KB Created: 2020-08-16 22:09:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 671de00d568111fda16ede7e75d47e68 SHA-1: 406780dc46ef47cc83a9e82f8a5e663a532d9415 SHA-256: 97b3b84cc95b8e9619107b0bb01bc4c399855c41844a3e553967dc44119c2d4e
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.com/pify?keyword=terraria+crafting+guide+pdf'. This URL is presented within the document body, disguised as a Terraria crafting guide. The PDF also exhibits characteristics of a link farm, with numerous embedded URLs, many hosted on cdn.shopify.com, suggesting an attempt to manipulate search engine results or distribute malicious content through seemingly benign links. No scripts were extracted, and the document body is heavily obfuscated, but the primary intent appears to be directing the user to a malicious site via the crafted link.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=terraria+crafting+guide+pdf
    • http://xixube.fumcsealy.org/uploads/1/3/1/3/131384281/4144989.pdf
    • https://cdn.shopify.com/s/files/1/0432/7964/6878/files/centrifugal_compressor_design_book.pdf
    • https://cdn.shopify.com/s/files/1/0431/0017/6544/files/96988482183.pdf
    • https://cdn.shopify.com/s/files/1/0433/6559/7342/files/bash_script_examples.pdf
    • https://cdn.shopify.com/s/files/1/0432/8721/6293/files/18946215248.pdf
    • https://cdn.shopify.com/s/files/1/0432/1450/4093/files/41205127896.pdf
    • https://cdn.shopify.com/s/files/1/0432/9940/5979/files/thinking_about_dilations_mathbits_worksheet_answers.pdf
    • https://cdn.shopify.com/s/files/1/0440/6041/0021/files/55611287855.pdf
    • https://cdn.shopify.com/s/files/1/0430/3945/7431/files/40637788586.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://terraria.gamepedia.com/Guide:Crafting_an_Ankh_Shiel
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006d3c.bin
879ff834e780a9dbc3c10b1100d9263632963402b65645defb4590e8f988b8a1
pdf-font-stream PDF embedded font (sfnt) at offset 0x6D3C 5060 bytes
font_01_sfnt_off00007e7c.bin
13bdad68eb87529b8bbfa0670c49cd1be8ba55b7bd1450f6bb69acf07390c663
pdf-font-stream PDF embedded font (sfnt) at offset 0x7E7C 15416 bytes
font_02_sfnt_off0000ae53.bin
b2cbfceaf44fc4a56d1321c5677f125dfbde6a5f8c873b6a17361dd7c2aa5302
pdf-font-stream PDF embedded font (sfnt) at offset 0xAE53 16232 bytes