Malicious PDF — malware analysis report

Static analysis result for SHA-256 9ac0d70be2f71d60…

MALICIOUS

PDF

50.5 KB Created: 2020-08-31 01:02:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7c9d4d41ad8a6513fcac2c220cbc7ad0 SHA-1: 3af8854719b2bef7b5fe7d903ab1a387ff5bdefa SHA-256: 9ac0d70be2f71d600e218f29631aa80a42a144b9053dad739af46ee79aa6fd45
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.cc/wix?keyword=panda+by+desiigner+download'. This URL is presented within the document body, likely as a lure to entice users to click on it. The file also exhibits characteristics of a link farm, with numerous embedded URLs, many pointing to Shopify domains, suggesting an attempt to obscure the malicious destination. The primary intent appears to be redirecting the user to a malicious site, potentially for further exploitation or credential harvesting.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=panda+by+desiigner+download
    • https://cdn.shopify.com/s/files/1/0431/9812/0094/files/regional_manager_interview_questions_and_answers.pdf
    • https://cdn.shopify.com/s/files/1/0430/4211/1650/files/61350540265.pdf
    • https://cdn.shopify.com/s/files/1/0432/1745/3211/files/25685175418.pdf
    • https://cdn.shopify.com/s/files/1/0438/4302/7106/files/balixivoriwis.pdf
    • https://static.usrfiles.com/ugd/078c79_ea9cd31b89344e7c97742c5b68bd5913.pdf
    • https://static.usrfiles.com/ugd/33a2e4_8a7f1eec25bd410e867280d19ccac01d.pdf
    • https://static.usrfiles.com/ugd/edb4a7_33e0518c9ab04ae7b1abe7c12264afff.pdf
    • https://static.usrfiles.com/ugd/66c878_a205af1bd8b94d7f953c581224385082.pdf
    • https://static.usrfiles.com/ugd/b8c837_a3fad402974c48eda4ff995286b5a2a6.pdf
    • https://static.usrfiles.com/ugd/1fa6dd_2f5680a2844341169b018955155bde3d.pdf
    • https://static.usrfiles.com/ugd/912de2_330432447a4146d8bf13ca1ce5ace0f1.pdf
    • https://cdn.shopify.com/s/files/1/0432/8787/1646/files/acquainted_with_the_night_poem.pdf
    • https://cdn.shopify.com/s/files/1/0435/6725/1615/files/8th_grade_vocabulary_words.pdf
    • https://cdn.shopify.com/s/files/1/0433/7932/7126/files/fapojowidufikaxasonike.pdf
    • https://cdn.shopify.com/s/files/1/0440/8115/2152/files/mitsubishi_fuso_service_manual.pdf
    • https://cdn.shopify.com/s/files/1/0434/0298/5637/files/gourmet_race_sheet_music_viola.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off00009a85.bin
0b61821f582dc227b9d84a6c82d277e0a364e59eb9ba487a34dabeef32327af8
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x9A85 19864 bytes
font_00_sfnt_off00004dfb.bin
b1f13eb000efe89dc686be6f70a38765d6ada3345adfbca006d18a4beea3defb
pdf-font-stream PDF embedded font (sfnt) at offset 0x4DFB 6820 bytes
font_01_sfnt_off00006583.bin
ef5bd5b731a30baa4436d8974722f56d005bb412c64527488fb4a26a816e9a97
pdf-font-stream PDF embedded font (sfnt) at offset 0x6583 5328 bytes
font_02_sfnt_off000077be.bin
7379ebf2dd37c1a9295a5ca178850fdceafee9ce6df011ca53507c31abbbdd5d
pdf-font-stream PDF embedded font (sfnt) at offset 0x77BE 10096 bytes