Malicious PDF — malware analysis report

Static analysis result for SHA-256 9e3a1233359e390c…

MALICIOUS

PDF

40.2 KB Created: 2020-08-12 08:01:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 934e88143e44c60f1fe3c4a651864eea SHA-1: 2beaba4cd5268ee50fa3305986181acc8a258798 SHA-256: 9e3a1233359e390cf1c4f0d52b56890f62985ca7a6c4dda0878135cd99f3cc82
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.001 Malicious Link T1059.001 PowerShell

The PDF contains multiple embedded links, with one identified as a malicious redirector. The heuristic PDF_MALICIOUS_REDIRECTOR_LINK indicates that the link at https://ttraff.com/wb?keyword=5.11%20tactec%20plate%20carrier%20manual is part of a known malicious infrastructure. Additionally, the PDF_SEO_LINK_FARM heuristic suggests a large number of external links, many hosted on Shopify, which is often used to disguise malicious content. No scripts were extracted from this sample, but the presence of malicious links strongly suggests a phishing or malware distribution attempt.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wb?keyword=5.11%20tactec%20plate%20carrier%20manual
    • http://files.floridapackages.ca/uploads/1/3/1/6/131607093/xefitezetabel.pdf
    • http://surad.berkleysteelers.net/uploads/1/3/2/6/132695471/pesamogugudowo_vezidasaduzi.pdf
    • http://beramapi.rebeccabevans.com/uploads/1/3/2/8/132814930/45388021f.pdf
    • http://files.immanuelchildrensfoundation.org/uploads/1/3/2/6/132681749/lozotemoxedu-lejelagokevabe-bipixibuvajofuj.pdf
    • https://cdn.shopify.com/s/files/1/0437/8004/6997/files/70443398698.pdf
    • https://cdn.shopify.com/s/files/1/0428/9904/6553/files/kiruresoporotogirixasaw.pdf
    • https://cdn.shopify.com/s/files/1/0432/0467/3697/files/2895221921.pdf
    • https://cdn.shopify.com/s/files/1/0440/6919/1832/files/pukoguwolixela.pdf
    • https://cdn.shopify.com/s/files/1/0432/6345/9486/files/81263825614.pdf
    • https://cdn.shopify.com/s/files/1/0434/2572/6625/files/wuvutijalofekafarubebuw.pdf
    • https://cdn.shopify.com/s/files/1/0435/5588/1111/files/bailar_pegados_acordes.pdf
    • https://cdn.shopify.com/s/files/1/0433/9898/7941/files/nazutu.pdf
    • https://cdn.shopify.com/s/files/1/0432/0660/7012/files/24445153753.pdf
    • https://cdn.shopify.com/s/files/1/0434/8523/3318/files/taylor_swift_red_album_cover.pdf
    • https://cdn.shopify.com/s/files/1/0432/8210/4478/files/adhyatma_ramayanam_tamil_download.pdf
    • https://cdn.shopify.com/s/files/1/0429/3450/1535/files/96921540712.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/23342697578.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005e72.bin
3674ffaef8f78f4bb7447767e9a50f254539097564797c2d6eceb15bf4c91c20
pdf-font-stream PDF embedded font (sfnt) at offset 0x5E72 5016 bytes
font_01_sfnt_off00006f63.bin
c9db001f971a2ec810adf669241857c4e1c2abed3ddc8e797a29070354689880
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F63 10608 bytes