Malicious PDF — malware analysis report

Static analysis result for SHA-256 ca24f67e342b4a29…

MALICIOUS

PDF

42.6 KB Created: 2020-09-03 09:50:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6222b690ebf2182d7f0490d432d5e7ec SHA-1: d39507cf70ad8fafd4a32b86e6fc191645061256 SHA-256: ca24f67e342b4a2987c6ef366598379732dbffb15409acf801b9b83c4b5356d7
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing for a malicious redirector link, which is also present in the document body. This link, 'https://ttraff.me/wix?keyword=what+is+ncr+non+conformance+report', is designed to lure users to a malicious site. The file also contains a large number of embedded links, many pointing to 'static.usrfiles.com', indicating a link farm strategy. The primary attack pattern is social engineering via a malicious link within the document.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=what+is+ncr+non+conformance+report
    • https://static.usrfiles.com/ugd/0c60a0_b043d97c4aec4f8f86c9ecedcd730b8d.pdf
    • https://static.usrfiles.com/ugd/b8c837_b4e0da035d4f48fab93217cb11bd96d3.pdf
    • https://static.usrfiles.com/ugd/b8c837_671c8c852bd8412b8eb3fa29d4ddc315.pdf
    • https://static.usrfiles.com/ugd/ae15ca_934d70b55bc646358080594ba811e307.pdf
    • https://static.usrfiles.com/ugd/64d889_ee0141bc2dee454d98fc68d547460ada.pdf
    • https://static.usrfiles.com/ugd/8ade13_6778c14b091e42d696e34106e25fcfb4.pdf
    • https://static.usrfiles.com/ugd/d5cf39_dda69885b5134105aae3483ffcc2246a.pdf
    • https://static.usrfiles.com/ugd/ce5d00_db077447e5404df5aac6e7038b58851c.pdf
    • https://static.usrfiles.com/ugd/96768c_d0cdfda880dd4adf96029a6fda893623.pdf
    • https://static.usrfiles.com/ugd/45fd81_24dca0eb1a01434e8965def451e86f86.pdf
    • https://static.usrfiles.com/ugd/b8c837_88574f32a474429e86cb0524108e9c2d.pdf
    • https://static.usrfiles.com/ugd/c4b402_e87527948e0b4a9aa81c8a52237eddbe.pdf
    • https://static.usrfiles.com/ugd/868b90_8f494653ef36475284bb6f5f3fbac2ea.pdf
    • https://static.usrfiles.com/ugd/be19e1_b35bb411d20c4459b3b47afc5cea8299.pdf
    • https://cdn.shopify.com/s/files/1/0439/3402/3848/files/bapegosejutanovemuvugi.pdf
    • https://cdn.shopify.com/s/files/1/0431/1855/9393/files/wejimilesunazibetenaxi.pdf
    • https://cdn.shopify.com/s/files/1/0436/2492/3298/files/85339875683.pdf
    • https://cdn.shopify.com/s/files/1/0434/9722/6402/files/xofipegipajufulijejo.pdf
    • https://cdn.shopify.com/s/files/1/0433/8289/8840/files/46867630699.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000694c.bin
e439a9919138bc69a0667401ff7945fa4e8af8bc2ae0ee0457ee542374d3e231
pdf-font-stream PDF embedded font (sfnt) at offset 0x694C 5236 bytes
font_01_sfnt_off00007aff.bin
0c18dd49ba549566599a23ad392512b48c835fa50e72e5025550107c4795587d
pdf-font-stream PDF embedded font (sfnt) at offset 0x7AFF 9996 bytes