Malicious PDF — malware analysis report

Static analysis result for SHA-256 a07e16946fdef16e…

MALICIOUS

PDF

44.9 KB Created: 2020-08-17 01:43:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8ba37aa32b6d6d050c64c21786e70424 SHA-1: 043900e4752cd1fd6d7dcc5503d4f94348626f63 SHA-256: a07e16946fdef16ecc1eb40e79110a21ad4c8a13d7da4c898be2a728531f2caa
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a link to a known malicious redirector, ttraff.com, which is disguised as a helpful resource for Excel formatting. This suggests a phishing or social engineering attack. The file also contains a large number of embedded links, many pointing to Shopify domains, which is characteristic of SEO link farm abuse to distribute malicious content. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the payload.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=bedingte+formatierung+ganze+zeile+markieren+excel+2010
    • http://sodor.sharlleteaesthetics.com/uploads/1/3/0/9/130969407/4389986.pdf
    • http://zimafita.haywardsheatheagles.com/uploads/1/3/1/6/131636612/kesama-xevoz-meledalixiweka-kimuwibu.pdf
    • http://files.scentsationalpamperingaccessories.com/uploads/1/3/2/6/132682565/980f13818d7.pdf
    • http://vagok.filter-equipment.com/uploads/1/3/1/1/131164250/4937439.pdf
    • http://wikevese.conversationcompass.com/uploads/1/3/1/8/131871453/f8d49dc86c.pdf
    • https://cdn.shopify.com/s/files/1/0427/6230/5702/files/zinizet.pdf
    • https://cdn.shopify.com/s/files/1/0432/7188/0870/files/28412436374.pdf
    • https://cdn.shopify.com/s/files/1/0429/5848/7715/files/reasoning_and_computer_aptitude_questions_and_answers.pdf
    • https://cdn.shopify.com/s/files/1/0432/2358/0839/files/71715844145.pdf
    • https://cdn.shopify.com/s/files/1/0434/4699/3052/files/glossary_of_life_insurance_terms.pdf
    • https://cdn.shopify.com/s/files/1/0431/4506/8699/files/nadej.pdf
    • https://cdn.shopify.com/s/files/1/0431/7285/5967/files/pearson_american_history_textbook.pdf
    • https://cdn.shopify.com/s/files/1/0449/5455/0440/files/4_class_english_book.pdf
    • https://cdn.shopify.com/s/files/1/0427/4749/4567/files/nepuvakabolefufun.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006d8b.bin
fd908a3dccd10c8dc848f91f53789bfa75d2d7f97b50633cbe20e094c0fb9080
pdf-font-stream PDF embedded font (sfnt) at offset 0x6D8B 5720 bytes
font_01_sfnt_off00008101.bin
2a0a21b325c7b3ff44a71b3024389601d3e9f72d2f644f3ceba11259e9ef18b8
pdf-font-stream PDF embedded font (sfnt) at offset 0x8101 11400 bytes