Malicious PDF — malware analysis report

Static analysis result for SHA-256 b6c18a6b04a7470c…

MALICIOUS

PDF

53.8 KB Created: 2020-08-11 19:42:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4af6b95e675a9d33d618b8551af50467 SHA-1: 25bf314b52a88d7e5ce9cc58ce5af18f8b5d55dc SHA-256: b6c18a6b04a7470c733c531a47a00c96a8937b203b4b5e9f73bfa80ac973bec1
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains embedded JavaScript and a critical heuristic firing indicates a malicious redirector link to ttraff.com. This suggests the document is designed to lure users to malicious infrastructure. Additionally, the PDF exhibits characteristics of a link farm, with numerous embedded URLs pointing to external resources, likely to improve search engine ranking or distribute further malicious content. The document body, though heavily obfuscated, contains the URL 'https://ttraff.com/pify?keyword=bruchrechnen+aufgaben+pdf+6.+klasse', reinforcing the redirector finding.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=bruchrechnen+aufgaben+pdf+6.+klasse
    • http://files.rescuedfirewood.com/uploads/1/3/0/9/130969938/81d8f865180.pdf
    • http://files.cuesign.org/uploads/1/3/0/7/130775747/worawiwiwunufe.pdf
    • http://files.avallecorsa.com/uploads/1/3/0/7/130776162/zorebuvisafid.pdf
    • http://files.northheroschool.org/uploads/1/3/1/4/131437044/8008111.pdf
    • http://mamumira.ndpharmabiotech.net/uploads/1/3/1/1/131163599/19be539e28ed7.pdf
    • https://cdn.shopify.com/s/files/1/0441/3738/2040/files/wivevexagowadakizujo.pdf
    • https://cdn.shopify.com/s/files/1/0430/2451/5229/files/74064800119.pdf
    • https://cdn.shopify.com/s/files/1/0440/7325/5062/files/16977214322.pdf
    • https://cdn.shopify.com/s/files/1/0434/9453/9429/files/nelagarewejisedefemudoru.pdf
    • https://cdn.shopify.com/s/files/1/0429/7005/4805/files/blue_book_of_grammar_free.pdf
    • https://cdn.shopify.com/s/files/1/0432/3606/5438/files/lifobifibigotimab.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/sigejorivuzogekos.pdf
    • https://cdn.shopify.com/s/files/1/0430/7379/8306/files/torodemotobofovabufami.pdf
    • https://cdn.shopify.com/s/files/1/0435/0266/5892/files/64636695806.pdf
    • https://cdn.shopify.com/s/files/1/0431/6761/3087/files/pitobatinob.pdf
    • https://cdn.shopify.com/s/files/1/0429/8942/0695/files/ruvugebedeporopubunos.pdf
    • https://cdn.shopify.com/s/files/1/0431/3651/6250/files/nuvovadapudevamipitavam.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008f7a.bin
3ee260f288b7b5c91ecd7e6d6edb9fd11019687adadb3ebb273614c9ada34bff
pdf-font-stream PDF embedded font (sfnt) at offset 0x8F7A 5856 bytes
font_01_sfnt_off0000a362.bin
0c179c374f74ba3bd091cef08aee699972f5f744f84137c2bedcf34bedb14845
pdf-font-stream PDF embedded font (sfnt) at offset 0xA362 11292 bytes