Malicious PDF — malware analysis report

Static analysis result for SHA-256 c8ee899602ed801f…

MALICIOUS

PDF

39.4 KB Created: 2020-09-06 17:15:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4f2c8b306d7b5d418c9df0a62aed2c95 SHA-1: c9db0ce52a81d0d1e0d5012b9eba881425afdd54 SHA-256: c8ee899602ed801f8f4ced36c26f78dcc1147887fc411cfc19cd73888b724a90
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.001 User Execution: Malicious Link

The PDF contains a mass of external links, including a critical redirector link to 'https://ttraff.link/wix?keyword=blackpink+playing+with+fire+lyrics+video'. This indicates a social engineering attempt to trick users into visiting a malicious site by disguising it as search results for popular content. The document body, though heavily obfuscated, also contains this URL, reinforcing the malicious intent. No scripts were extracted, and the PDF structure itself does not indicate further exploitation beyond the embedded links.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=blackpink+playing+with+fire+lyrics+video
    • https://cdn.shopify.com/s/files/1/0434/8936/2086/files/game_dev_tycoon_cheats_android.pdf
    • https://cdn.shopify.com/s/files/1/0431/6050/2421/files/kezurupetibizalapog.pdf
    • https://cdn.shopify.com/s/files/1/0433/4852/5206/files/12081968785.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/58014629257.pdf
    • https://static.usrfiles.com/ugd/f1d680_7ce248ca6df847cab1048c10d3b47c7e.pdf
    • https://static.usrfiles.com/ugd/aec2ea_9b9189c80de142d38c99890fc5cdd5f6.pdf
    • https://static.usrfiles.com/ugd/4fb05f_abc7262c16dc439f85587e78d9341714.pdf
    • https://static.usrfiles.com/ugd/7c3584_8e5f487a54cc4612a76c1fd741df619a.pdf
    • https://static.usrfiles.com/ugd/ee9d3f_092fe35669ee4a52a86a77e02e3fd60c.pdf
    • https://static.usrfiles.com/ugd/96768c_7dec0c3325084590b1397996ab1c63b0.pdf
    • https://static.usrfiles.com/ugd/b8c837_0b569ee11d2e4fa09dd267c09b206627.pdf
    • https://static.usrfiles.com/ugd/b8c837_b5fbdb21f8294122bed343ea0e67c279.pdf
    • https://static.usrfiles.com/ugd/83b1b3_176bd2cc9b3a4f9f87f5345bcaad6d5c.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004e36.bin
e887045285563686d8e0e1a43a2bd02c71590e7bc57f77eef4f3b13cee2092a4
pdf-font-stream PDF embedded font (sfnt) at offset 0x4E36 5572 bytes
font_01_sfnt_off00006143.bin
5803ece080701eeb03f9c7baa576de5db8c32f923eff56f5e03bacfabf99bff3
pdf-font-stream PDF embedded font (sfnt) at offset 0x6143 9760 bytes
font_02_sfnt_off00008292.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0x8292 4324 bytes