Malicious PDF — malware analysis report

Static analysis result for SHA-256 ab99127acedf4a92…

MALICIOUS

PDF

45.6 KB Created: 2020-08-30 15:32:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3a54a7da7cfddb70dd5becd62bbb8ae1 SHA-1: 1d5b8075097c92b30f81fbb35d6ec7dd1aef5149 SHA-256: ab99127acedf4a92e791bf6568b276ea0a350e15ab49ecd4e04ae7901ae1a33f
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains multiple embedded links, including one identified as a malicious redirector. The presence of a 'download button' heuristic and the embedded URL strongly suggest a social engineering attack. The primary malicious URL is ttraff.com, which redirects to content related to 'film bedevilled 2010 sub indo'. The document body, though heavily obfuscated, also contains this URL and other PDF links, indicating a link farm strategy to distribute malicious content.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=film+bedevilled+2010+sub+indo
    • https://cdn.shopify.com/s/files/1/0432/1158/7752/files/18742092388.pdf
    • https://cdn.shopify.com/s/files/1/0437/4642/7031/files/tigezatunigowepozesipuxi.pdf
    • https://cdn.shopify.com/s/files/1/0431/2599/7722/files/rizotujifiwozar.pdf
    • https://cdn.shopify.com/s/files/1/0430/0469/0581/files/45881981017.pdf
    • https://cdn.shopify.com/s/files/1/0434/4964/7271/files/holly_jolly_christmas_piano_sheet_music_free.pdf
    • https://cdn.shopify.com/s/files/1/0428/8030/3267/files/9231428536.pdf
    • https://static.usrfiles.com/ugd/3ab5ed_e2b1e17cba6b4e069066c2457736fe30.pdf
    • https://static.usrfiles.com/ugd/69695d_f642e33f8a3742ee80e806dd4a626f79.pdf
    • https://static.usrfiles.com/ugd/b8c837_35eddabeec164694aa16ed90af27fc0c.pdf
    • https://static.usrfiles.com/ugd/b8c837_09ff9eee10534719a34530a46cfcff34.pdf
    • https://static.usrfiles.com/ugd/b8c837_a8de0b5250514b5fb7de2c281ec5ba82.pdf
    • https://static.usrfiles.com/ugd/b8c837_74b57338578845ef8460befcdf8554ad.pdf
    • https://static.usrfiles.com/ugd/271e65_4d2bfe4ce1d84e279b00695a52f24294.pdf
    • https://static.usrfiles.com/ugd/ab922d_e6b63f74f1ae4e3d8a3a15360969c679.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006a1a.bin
cc12a13d627b0bcfb86c88b9857f6babfbbaf6ba9060a15195528b8ddd3592e7
pdf-font-stream PDF embedded font (sfnt) at offset 0x6A1A 5144 bytes
font_01_sfnt_off00007b59.bin
1e53ac68b53c38ceacecf3f1639f28b0cc23e038c9ddce9ad139fcad9643d2f1
pdf-font-stream PDF embedded font (sfnt) at offset 0x7B59 2644 bytes
font_02_sfnt_off0000859f.bin
b4e3701993a2ac7f191a07c0edabc17b7ea2a0a3874e4e0110bfd689a3d77e71
pdf-font-stream PDF embedded font (sfnt) at offset 0x859F 10316 bytes