Malicious PDF — malware analysis report

Static analysis result for SHA-256 a99acfb6396a0420…

MALICIOUS

PDF

35.6 KB Created: 2020-08-20 21:18:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7ca00f04d051afc6d1561c19193252b9 SHA-1: a7906711036d0b51d8181c794294f55208e94896 SHA-256: a99acfb6396a042091f9724353dd1f789664b2fce4ae782a70b41b94cbc69b08
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, many of which point to Shopify domains, but one critical link directs to a known malicious redirector. The document body, though partially corrupted, contains text that appears to be a title and a URL, suggesting a lure to a malicious site. The primary malicious URL identified is ttraff.com, which is used to redirect users to further malicious content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=anthem+lights+class+of+2017+mashup
    • http://files.therabbitmansion.com/uploads/1/3/1/1/131163788/25d02e8145241.pdf
    • http://gajexokam.goingtruegreen.com/uploads/1/3/1/8/131857419/lilokeka.pdf
    • http://watoxan.oldwisdomnewmoon.com/uploads/1/3/2/7/132740285/zerodavubata.pdf
    • http://files.oqls.org/uploads/1/3/0/7/130775520/wowipodukijikok_kawazavak_juvud_mapuvebalomur.pdf
    • https://cdn.shopify.com/s/files/1/0433/6756/3429/files/20671968180.pdf
    • https://cdn.shopify.com/s/files/1/0429/1949/3785/files/10922827058.pdf
    • https://cdn.shopify.com/s/files/1/0429/6785/9359/files/ruzaxuni.pdf
    • https://cdn.shopify.com/s/files/1/0431/5856/9128/files/30777144363.pdf
    • https://cdn.shopify.com/s/files/1/0430/6547/5229/files/37099037980.pdf
    • https://cdn.shopify.com/s/files/1/0428/3655/7987/files/76514314038.pdf
    • https://cdn.shopify.com/s/files/1/0431/1243/1776/files/google_translate_english_to_indonesia.pdf
    • https://cdn.shopify.com/s/files/1/0431/8353/8333/files/12388863977.pdf
    • https://cdn.shopify.com/s/files/1/0432/5077/8275/files/convert_byte_array_to_file.pdf
    • https://cdn.shopify.com/s/files/1/0430/9952/1178/files/lewiston_idaho_steelhead_fishing_report.pdf
    • https://cdn.shopify.com/s/files/1/0431/5391/6060/files/turtle_the_incredible_journey_worksheet.pdf
    • https://cdn.shopify.com/s/files/1/0433/9499/0243/files/love_is_on_the_way_guitar_tab.pdf
    • https://cdn.shopify.com/s/files/1/0440/3894/6981/files/chain_armor_minecraft.pdf
    • https://cdn.shopify.com/s/files/1/0433/9177/8965/files/73116528348.pdf
    • https://cdn.shopify.com/s/files/1/0428/1381/6995/files/tanerijelepudodesefogijul.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004deb.bin
a9c160262786626d3456cde9dbf78d87aac797739b3b4ba52a18960a6f695fb6
pdf-font-stream PDF embedded font (sfnt) at offset 0x4DEB 5728 bytes
font_01_sfnt_off00006150.bin
7688b140230bfb484dc1caf5c3e2311f5f110af9af26d6b6c5ab897131409eaf
pdf-font-stream PDF embedded font (sfnt) at offset 0x6150 9300 bytes