Malicious PDF — malware analysis report

Static analysis result for SHA-256 a2eb07beb1b90524…

MALICIOUS

PDF

47.9 KB Created: 2020-09-15 05:54:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8be09c48b2b7bff3b1b40ec8c3c39096 SHA-1: b26e15085bba53bfb1b100adb93713d6e0b575de SHA-256: a2eb07beb1b9052459fdb8f16c3b52532fb0aacbe7992c819a72bbe0b2699cd1
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous embedded links, a common tactic for link farms and redirectors. One critical heuristic identified a link to a known malicious redirector infrastructure, specifically `https://ttraff.club/pify?keyword=btd+6+mod+apk+ios`, which is presented as a lure for a game mod. The document body also contains this URL, reinforcing the social engineering aspect. The presence of many external PDF links suggests an attempt to manipulate search engine rankings or distribute further malicious content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/pify?keyword=btd+6+mod+apk+ios
    • http://dexuxase.rhoganenterprises.com/uploads/1/3/1/4/131453858/bozevexufinigafumeb.pdf
    • http://vejumit.gastrocycling.com/uploads/1/3/1/0/131071252/milipovi-vuviguwapo-gaverurel.pdf
    • http://kozuzuno.bzdickstudio.com/uploads/1/3/1/3/131379730/kabub.pdf
    • https://static.usrfiles.com/ugd/957c7b_67e203e607644cc39f4446852f7cff0d.pdf
    • https://static.usrfiles.com/ugd/9e53d4_8c2533ed26824040a5128b946a83126a.pdf
    • https://static.usrfiles.com/ugd/fbccce_53d379510e0c47db9dd1d47f91857f0f.pdf
    • https://static.usrfiles.com/ugd/13ae68_ab3c1da606f34aa990ba01451a28c023.pdf
    • https://cdn.shopify.com/s/files/1/0432/9380/2662/files/vasorarevodowuwexilafomon.pdf
    • https://cdn.shopify.com/s/files/1/0432/4907/4344/files/fidanuniloxusakev.pdf
    • https://cdn.shopify.com/s/files/1/0429/8512/8099/files/45289618240.pdf
    • https://cdn.shopify.com/s/files/1/0428/4389/8019/files/battlefield_5_wiki_guide.pdf
    • https://cdn.shopify.com/s/files/1/0430/5344/9367/files/xejililodijomupavuwe.pdf
    • https://static.usrfiles.com/ugd/6846fe_882df5ac28f649b681656ac331772a5d.pdf
    • https://static.usrfiles.com/ugd/68ec51_c26ef688ae9b48febaa4420146e90262.pdf
    • https://static.usrfiles.com/ugd/361f4b_75b1c25a13a841ad99a09a11ff0e2197.pdf
    • https://static.usrfiles.com/ugd/5be868_ed0a98e2f8e14d91878ec59d4a34332f.pdf
    • https://static.usrfiles.com/ugd/b8c837_07ccc022868442ab9af9b159a8e2e6a3.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000711d.bin
5aa20e762ba92e5b0fc1746b7e66e32797731cce968e502d37821c66562417b4
pdf-font-stream PDF embedded font (sfnt) at offset 0x711D 4808 bytes
font_01_sfnt_off00008176.bin
99ce422f2f416df79da5b7ed26b0e7b9543ac1bfdc34a3250ab50f6d7da20cb9
pdf-font-stream PDF embedded font (sfnt) at offset 0x8176 10304 bytes
font_02_sfnt_off0000a4af.bin
a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f
pdf-font-stream PDF embedded font (sfnt) at offset 0xA4AF 4324 bytes