Malicious PDF — malware analysis report

Static analysis result for SHA-256 b37680ac2e9e4cfd…

MALICIOUS

PDF

50.7 KB Created: 2020-08-31 04:21:15 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7004b8edae6a02f05113add0a340c915 SHA-1: ab850c1e5aa02460c6d42b956e17c4b3dd10c237 SHA-256: b37680ac2e9e4cfd64f0225d33f710634b147a42d9c3a118566e5823ae60e872
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.club/wix?keyword=la+cajita+feliz+del+metro'. Additionally, it exhibits a PDF link farm heuristic, with numerous links to PDFs hosted on cdn.shopify.com. The document body contains obfuscated text that includes the malicious redirector URL, suggesting an attempt to lure users to a malicious site. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=la+cajita+feliz+del+metro
    • https://cdn.shopify.com/s/files/1/0434/9113/1557/files/6558643806.pdf
    • https://cdn.shopify.com/s/files/1/0432/5117/1478/files/76822551461.pdf
    • https://cdn.shopify.com/s/files/1/0438/3024/7584/files/the_captain_s_daughter_pushkin.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/puwojadudabub.pdf
    • https://cdn.shopify.com/s/files/1/0432/8207/1716/files/prepositions_of_place_agenda_web.pdf
    • https://cdn.shopify.com/s/files/1/0433/0065/1158/files/bare_infinitive_and_full_infinitive_exercises.pdf
    • https://cdn.shopify.com/s/files/1/0462/3925/2631/files/jevagisukeworebalimupiro.pdf
    • https://cdn.shopify.com/s/files/1/0436/4104/5145/files/animals_for_kids_vocabulary.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/73930450062.pdf
    • https://cdn.shopify.com/s/files/1/0432/5834/7688/files/candidose_oesophagienne.pdf
    • https://cdn.shopify.com/s/files/1/0440/4926/8886/files/50466087353.pdf
    • https://cdn.shopify.com/s/files/1/0433/0265/0011/files/7th_grade_math_experimental_probability_worksheets.pdf
    • https://cdn.shopify.com/s/files/1/0429/4439/7468/files/45862072848.pdf
    • https://cdn.shopify.com/s/files/1/0434/7835/2022/files/best_internet_accountability_software_for_android.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006fea.bin
69d65f99a0dc354a7d1528cc643526121ec393baf5f443442de8ead2d2572a8a
pdf-font-stream PDF embedded font (sfnt) at offset 0x6FEA 5056 bytes
font_01_sfnt_off00008110.bin
348e8d5fd97559578da4ad5cc06cdc939906f3cad42e36a4af6db25328cfe807
pdf-font-stream PDF embedded font (sfnt) at offset 0x8110 11856 bytes
font_02_sfnt_off0000a7ea.bin
20dc835fdb26e5c8b2bf371a74de3f1f2251d0d540cd54084ecb3d27d8cc4587
pdf-font-stream PDF embedded font (sfnt) at offset 0xA7EA 16076 bytes