Malicious PDF — malware analysis report

Static analysis result for SHA-256 be9be85595fd1eff…

MALICIOUS

PDF

46.0 KB Created: 2020-08-19 04:09:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c320a05a5024afe8d9885376773853d0 SHA-1: c3f88beae9a9e0b06dca00004a80b540de499025 SHA-256: be9be85595fd1eff11903e41862b3d12fde37cb8f688b250e128025f00c1bae0
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. Additionally, it exhibits a PDF link farm heuristic, with numerous links pointing to Shopify domains, one of which is identified as the initial lure. The document body also contains the text 'Macro combine data from multiple sheets' and the malicious URL, suggesting a social engineering pretext to entice clicks. The presence of a call-to-action phrase further supports a malicious workflow.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=macro+combine+data+from+multiple+sheets
    • http://files.brianduford.com/uploads/1/3/1/8/131856212/26a8648c9e06b.pdf
    • http://xifigi.santiagocimadevilla.com/uploads/1/3/0/9/130969504/21ddf7408766a95.pdf
    • http://files.brissaeden.com/uploads/1/3/2/6/132681757/d3784.pdf
    • https://cdn.shopify.com/s/files/1/0432/4494/5571/files/architectural_acoustics_marshall_long_download.pdf
    • https://cdn.shopify.com/s/files/1/0433/6012/5080/files/cache_database_odbc_driver.pdf
    • https://cdn.shopify.com/s/files/1/0435/2439/1067/files/37194524715.pdf
    • https://cdn.shopify.com/s/files/1/0433/4452/7511/files/89311303725.pdf
    • https://cdn.shopify.com/s/files/1/0447/6128/4757/files/how_to_install_wifi_on_linux_mint.pdf
    • https://cdn.shopify.com/s/files/1/0435/0155/1771/files/mupasarekovifabe.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/lezoxaxus.pdf
    • https://cdn.shopify.com/s/files/1/0436/0513/1421/files/38473800819.pdf
    • https://cdn.shopify.com/s/files/1/0431/7092/2655/files/4043252289.pdf
    • https://cdn.shopify.com/s/files/1/0434/3191/9765/files/definition_of_knowledge_management.pdf
    • https://cdn.shopify.com/s/files/1/0439/8520/7454/files/fevefetipivikoz.pdf
    • https://cdn.shopify.com/s/files/1/0430/1327/5811/files/rakaxogexewonuvuga.pdf
    • https://cdn.shopify.com/s/files/1/0431/3962/9218/files/reading_and_writing_skills_grade_11_download.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000067fc.bin
20550c248e3fea8e64fdea4d481e8d34a9cfac8a24717ca8b8a81f20993b5cb7
pdf-font-stream PDF embedded font (sfnt) at offset 0x67FC 5424 bytes
font_01_sfnt_off00007a2f.bin
2750e673153d3eb5eeb213139029dfd97cd6be94adaa1401ba3cc848847a3dce
pdf-font-stream PDF embedded font (sfnt) at offset 0x7A2F 10060 bytes
font_02_sfnt_off00009c99.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0x9C99 4324 bytes