Malicious PDF — malware analysis report

Static analysis result for SHA-256 b2d1d185966cad9a…

MALICIOUS

PDF

42.4 KB Created: 2020-09-06 08:15:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f3a251784e312009d558233c784c7bdc SHA-1: 6d2ae8960ce369933cb6804a4635314652b5cc03 SHA-256: b2d1d185966cad9aeacd84d0133d207d28dfe933539794b1627878b41a513707
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.me/wix?keyword=bollywood+full+movie++hd+print'. This URL is presented within the document body, alongside numerous other PDF links, suggesting a link farm or redirection tactic. The presence of a 'download button' heuristic further supports the attack pattern of luring users to click malicious links. No scripts were extracted, and the document body content is heavily obfuscated, but the primary malicious intent is clear from the redirector URL.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=bollywood+full+movie++hd+print
    • https://cdn.shopify.com/s/files/1/0435/6148/4447/files/46307680612.pdf
    • https://cdn.shopify.com/s/files/1/0428/8974/0441/files/gibilozefipovibiwuzifodiv.pdf
    • https://cdn.shopify.com/s/files/1/0433/7680/3990/files/misipegekinevaresevatano.pdf
    • https://cdn.shopify.com/s/files/1/0437/7106/8565/files/theistic_existentialism.pdf
    • https://static.usrfiles.com/ugd/0a052f_f32bad966c484f1293b0741a1d8b00ea.pdf
    • https://cdn.shopify.com/s/files/1/0434/1674/8190/files/zururulakaxuwofofo.pdf
    • https://cdn.shopify.com/s/files/1/0428/8865/9100/files/donuro.pdf
    • https://static.usrfiles.com/ugd/bfbc46_7927dbaa308f4db8aec6d4c666f55507.pdf
    • https://static.usrfiles.com/ugd/e4bc37_1eac665c5e55403784b27f74434d8f2f.pdf
    • https://static.usrfiles.com/ugd/516793_548c495edffb476fb956cf7a559bc974.pdf
    • https://static.usrfiles.com/ugd/b8c837_b71340a52ce44950926d405c7b26cc05.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000052db.bin
1f523beb1e8b4e08373d9404cf961812acc15299b099601cf2e1525680136324
pdf-font-stream PDF embedded font (sfnt) at offset 0x52DB 5196 bytes
font_01_sfnt_off00006482.bin
024d2ee2e8452914d56d5b1840a27c0d6085431c7052856f321f4ca53e63577f
pdf-font-stream PDF embedded font (sfnt) at offset 0x6482 10160 bytes
font_02_sfnt_off00008771.bin
ebd2804bff382343e08f6a42dc45f69f4e794c08b23908ae60ba78ededae74b1
pdf-font-stream PDF embedded font (sfnt) at offset 0x8771 16164 bytes