Malicious PDF — malware analysis report

Static analysis result for SHA-256 c8c5e31ddd8878af…

MALICIOUS

PDF

43.7 KB Created: 2020-09-02 13:57:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3ea1b8c5935eb9c1c4fa21baeb6d2c4e SHA-1: 83b4f485f679c3aa1be69173aedcd95228ea51ae SHA-256: c8c5e31ddd8878affd2513d1c1e4fadac7cb166ca1003b4e8e58ef15742de0fc
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.cc'. This indicates the document's primary purpose is to redirect users to potentially harmful content. The document also contains a PDF link farm heuristic, suggesting an attempt to artificially inflate search engine rankings or distribute malicious links. No scripts were extracted, but the presence of the malicious redirector is sufficient evidence of malicious intent.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=new+arabic+remix+songs+free
    • https://cdn.shopify.com/s/files/1/0440/5755/9190/files/14913593240.pdf
    • https://cdn.shopify.com/s/files/1/0438/8729/6680/files/ijazat_movie_all_song.pdf
    • https://cdn.shopify.com/s/files/1/0430/8212/1377/files/19007462397.pdf
    • https://cdn.shopify.com/s/files/1/0435/9369/5391/files/biryani_recipe_download.pdf
    • https://cdn.shopify.com/s/files/1/0429/5963/4591/files/pidosonogonezuwuvizisatus.pdf
    • https://cdn.shopify.com/s/files/1/0429/6789/2131/files/42687910337.pdf
    • https://cdn.shopify.com/s/files/1/0432/8233/3851/files/20246951929.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/21154843933.pdf
    • https://static.usrfiles.com/ugd/b8c837_f3fe03b5f37441ef8720a6ec74cb2d99.pdf
    • https://static.usrfiles.com/ugd/e3834b_a3f2a89273a6423aae24ae51e68a8957.pdf
    • https://static.usrfiles.com/ugd/b77b08_8c7f19ac79844f3189bb799dd294a1f7.pdf
    • https://static.usrfiles.com/ugd/221f3a_b705ee886fa545aa8041a631ba0daeab.pdf
    • https://static.usrfiles.com/ugd/3b5dd9_dbfbe802f76542f3967caaedabe8a9c8.pdf
    • https://static.usrfiles.com/ugd/bf650e_9f70ee17633d4d24be27954c505931cf.pdf
    • https://static.usrfiles.com/ugd/b8c837_e4b7d39b72a64b3a9ebd791606d268f6.pdf
    • https://static.usrfiles.com/ugd/bdeb4c_da3e91e500b24925a95773e8dcc2d0e2.pdf
    • https://static.usrfiles.com/ugd/b8c837_e2861ef9ee8442e4bafe2cbde97fde5e.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004c63.bin
1327ebfe7ad9220a6d80e5d85fc15487972e1d6c2470e34721899e4d5d66ac9d
pdf-font-stream PDF embedded font (sfnt) at offset 0x4C63 5440 bytes
font_01_sfnt_off00005eee.bin
dc36fd44d9700552e77de42e1b05e0e02ffffc77e06e04cf8bb1657347d299f7
pdf-font-stream PDF embedded font (sfnt) at offset 0x5EEE 10144 bytes
font_02_sfnt_off000081f0.bin
dabf0ccc451caf4864c9b22ca91318a92e8f625b469dd0561edf59b451c7a792
pdf-font-stream PDF embedded font (sfnt) at offset 0x81F0 18776 bytes