Malicious PDF — malware analysis report

Static analysis result for SHA-256 b85a3795538c9545…

MALICIOUS

PDF

29.6 KB Created: 2020-08-18 18:47:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5442d53f80b8b249681740606f9ba874 SHA-1: 3571e31ebfce70d850fd32bd607647052607ea66 SHA-256: b85a3795538c954594868a3cfd802e77469627274dabdd43caccda02881e023d
140 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF was identified as an image-only lure, a common phishing tactic. It contains a critical heuristic indicating it links to known malicious redirector infrastructure, specifically 'https://ttraff.com/pify?keyword=good+bye+hd+images'. Additionally, it exhibits characteristics of a PDF link farm, embedding numerous external links, many hosted on cdn.shopify.com, likely to obscure the malicious redirector or for SEO manipulation. The document body contains garbled text but includes the malicious redirector URL.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 29 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=good+bye+hd+images
    • http://files.banahawhealsspa.com/uploads/1/3/2/8/132814071/wotigijo_vejevaweg.pdf
    • https://cdn.shopify.com/s/files/1/0434/0223/1971/files/mulipode.pdf
    • https://cdn.shopify.com/s/files/1/0429/5367/0822/files/business_line_newspaper_download.pdf
    • https://cdn.shopify.com/s/files/1/0433/8899/3703/files/california_dmv_dl_44_form.pdf
    • https://cdn.shopify.com/s/files/1/0429/3145/4119/files/fundamental_of_electrical_engineering.pdf
    • https://cdn.shopify.com/s/files/1/0430/8143/3242/files/dumilaposexudije.pdf
    • https://cdn.shopify.com/s/files/1/0430/2385/9873/files/free_pogo_games.pdf
    • https://cdn.shopify.com/s/files/1/0436/9596/4314/files/xipozigune.pdf
    • https://cdn.shopify.com/s/files/1/0433/5904/3749/files/81355461056.pdf
    • https://cdn.shopify.com/s/files/1/0427/5427/7532/files/sadoduropujemavizifol.pdf
    • https://cdn.shopify.com/s/files/1/0428/5965/9420/files/makerere_university_courses.pdf
    • https://cdn.shopify.com/s/files/1/0432/7922/0891/files/68010702919.pdf
    • https://cdn.shopify.com/s/files/1/0429/0691/0887/files/gepib.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003cc1.bin
d9f423b33c9ed9de00d7c5697ec4b7d517c06976c5ff06655dce27ecf085fd8d
pdf-font-stream PDF embedded font (sfnt) at offset 0x3CC1 5384 bytes
font_01_sfnt_off00004f04.bin
98bd3eb7d137f467fe3b1e8faffb031bc3c9e775e1537e582cbc84434481fbaf
pdf-font-stream PDF embedded font (sfnt) at offset 0x4F04 7932 bytes