Malicious PDF — malware analysis report

Static analysis result for SHA-256 c45c3ab0bafe69e9…

MALICIOUS

PDF

68.8 KB Created: 2020-08-31 12:14:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7c38ffd1e5f0473b40ca01dfb002eb95 SHA-1: 50b7f376512379dfd7d0316be2eeb6e1ba833a01 SHA-256: c45c3ab0bafe69e9c233108527b1883db81006c50af15e82267e0bd355e7ce8c
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a malicious redirector link pointing to 'ttraff.com'. Additionally, it exhibits characteristics of a PDF link farm, with numerous external links, many of which are hosted on Shopify. The document body, though heavily obfuscated, contains the same URL as the malicious redirector. This suggests the primary goal is to redirect the user to a malicious site.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=diccionario+etimologico+pdf
    • https://cdn.shopify.com/s/files/1/0439/0184/5659/files/jumbling_reasoning_questions.pdf
    • https://cdn.shopify.com/s/files/1/0432/1483/1780/files/82225662780.pdf
    • https://cdn.shopify.com/s/files/1/0438/3129/6160/files/water_quality_data_analysis_and_interpretation.pdf
    • https://cdn.shopify.com/s/files/1/0440/4045/4294/files/azure_iot_tutorial.pdf
    • https://cdn.shopify.com/s/files/1/0448/1361/5264/files/miller_welder_replacement_parts.pdf
    • https://cdn.shopify.com/s/files/1/0433/7988/4195/files/7_11_beyonce_mp3.pdf
    • https://static.usrfiles.com/ugd/2274a7_2117f02018634703b6a1103b36fcbc1c.pdf
    • https://static.usrfiles.com/ugd/599f1c_c8b65e030a7b4517bdb197b6e860fb5f.pdf
    • https://static.usrfiles.com/ugd/b8c837_32f6563762d24f5e9b8764a9afd3a3ee.pdf
    • https://cdn.shopify.com/s/files/1/0435/2134/3647/files/catalogo_avon_13_2020.pdf
    • https://cdn.shopify.com/s/files/1/0428/8076/2023/files/43871114136.pdf
    • https://cdn.shopify.com/s/files/1/0431/0876/1764/files/jekatofigimimoluridox.pdf
    • https://cdn.shopify.com/s/files/1/0428/9173/9295/files/77310675086.pdf
    • https://cdn.shopify.com/s/files/1/0433/2270/4030/files/ligivufizomonixa.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009ce7.bin
359ad26b63d700afde855473653be601daaadf5e3f3f455fda69f3d019e9235e
pdf-font-stream PDF embedded font (sfnt) at offset 0x9CE7 5296 bytes
font_01_sfnt_off0000aecf.bin
f69d050477d08b6bf3141a0bc6a813492f84e09dc37c17800a4cf4e3d9f690a3
pdf-font-stream PDF embedded font (sfnt) at offset 0xAECF 19480 bytes
font_02_sfnt_off0000e88d.bin
d4426f440da8b3063d4a62c113b938afc182b24b3a34933c5ee70df3af2f3432
pdf-font-stream PDF embedded font (sfnt) at offset 0xE88D 18164 bytes