Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f6719a85414e141…

MALICIOUS

PDF

55.0 KB Created: 2020-09-01 09:32:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4ecc48fefba2645205e4b248e0a7781a SHA-1: ce6dc30b7894476ef12a8325752a75539a2a8ff3 SHA-256: 9f6719a85414e141df9944ef293840026cfc83ab67e04ff69beaad482ce630e5
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a link farm and a malicious redirector, disguised as a download for 'Home Alone movie 480p'. The primary malicious URL is ttraff.cc, which is known to host redirectors. The document body also contains numerous links to other PDFs hosted on shopify.com, likely part of a SEO link farm to improve search engine ranking for malicious content.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=home+alone+movie++480p
    • https://cdn.shopify.com/s/files/1/0433/2870/0571/files/gikej.pdf
    • https://cdn.shopify.com/s/files/1/0428/2338/5247/files/nuxuzedivuz.pdf
    • https://cdn.shopify.com/s/files/1/0431/0705/7825/files/ielts_vocabulary_for_writing_task_1.pdf
    • https://cdn.shopify.com/s/files/1/0431/1390/6327/files/kepabubonizaruwubo.pdf
    • https://static.usrfiles.com/ugd/b8c837_9111885aa33d4c6ead162a81e014f658.pdf
    • https://static.usrfiles.com/ugd/738632_775769babaf74c67bccc5e3b294a9258.pdf
    • https://cdn.shopify.com/s/files/1/0434/2359/6711/files/wordly_wise_book_7_lesson_3_answer_key.pdf
    • https://cdn.shopify.com/s/files/1/0430/2536/7193/files/blouse_cutting_and_stitching_in_tamil_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0429/9443/4202/files/90311466791.pdf
    • https://static.usrfiles.com/ugd/83e24f_703e623027a64d1ca1610229f52c53e3.pdf
    • https://static.usrfiles.com/ugd/ceb2e8_580f65cba9974c40adf7e9e4c71e9134.pdf
    • https://static.usrfiles.com/ugd/e745be_8f8d4567e42f44848e61b1c0bdcfd69e.pdf
    • https://static.usrfiles.com/ugd/e3ed1f_be5f66a7da8744b1a4e90b72fd827f99.pdf
    • https://static.usrfiles.com/ugd/6d59ab_3f867f3cc6524af588acaa2b8482e5cf.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006737.bin
133ec3a27a4b88a23d7adaef8158a7d3e2b51cec5a06b677b6470a6541894951
pdf-font-stream PDF embedded font (sfnt) at offset 0x6737 5136 bytes
font_01_sfnt_off000078a7.bin
25d2fbfb5dd46bce752f1a10cbb8fe29a5ece10bd9e4a33cfa5ea6c363d8700b
pdf-font-stream PDF embedded font (sfnt) at offset 0x78A7 20968 bytes
font_02_sfnt_off000098da.bin
fc56fa02dbe3458291c5fb7062dec2b01f2226dd21b4eff9ce88880a69c4a691
pdf-font-stream PDF embedded font (sfnt) at offset 0x98DA 2276 bytes
font_03_sfnt_off0000a2a4.bin
9f4d1875fe79a33dd12c2198a423e01f7062ff452ba62e13a74164ae50ec29c2
pdf-font-stream PDF embedded font (sfnt) at offset 0xA2A4 10224 bytes
font_04_sfnt_off0000c582.bin
589f2a64e89766a8ae62896ea8444fa1a87810255c984bbc4fd2a260c4929d56
pdf-font-stream PDF embedded font (sfnt) at offset 0xC582 2056 bytes