Malicious PDF — malware analysis report

Static analysis result for SHA-256 ce54695210b1777f…

MALICIOUS

PDF

37.5 KB Created: 2020-08-11 13:50:59 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5265213e1a75ea71dfcd5db4dedb45ab SHA-1: 2a30254ecc13bed59484f06f874e5a6b060b8a15 SHA-256: ce54695210b1777fe661087dbd02c4b639084346306aa64902a11891e8395d22
160 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious Link T1204.001 User Execution: Malicious Link T1059.003 Command and Scripting Interpreter: Windows Command Shell

The PDF contains a mass of external links, many pointing to shopify.com domains, but one critical link to 'ttraff.cc' is identified as a malicious redirector. The document body also contains text suggesting the user should copy or paste clipboard content into a shell, indicating a potential command execution lure. The primary intent appears to be redirecting the user to malicious infrastructure via the 'ttraff.cc' URL.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=catalano+colori+pdf
    • http://files.evenaberle.studio/uploads/1/3/0/8/130813876/petomumo.pdf
    • http://files.blastostreetwear.com/uploads/1/3/1/4/131410736/f1a956.pdf
    • http://files.demidemi.net/uploads/1/3/2/6/132695535/3263835.pdf
    • http://files.llevataps.com/uploads/1/3/2/6/132681949/rurowutenusuviwe.pdf
    • https://cdn.shopify.com/s/files/1/0429/7624/7971/files/69136089427.pdf
    • https://cdn.shopify.com/s/files/1/0437/6566/1845/files/minecraft_iron_golem_farm_1._14.pdf
    • https://cdn.shopify.com/s/files/1/0437/7418/1534/files/minecraft_save_editor.pdf
    • https://cdn.shopify.com/s/files/1/0431/4166/0826/files/duzuvivexezube.pdf
    • https://cdn.shopify.com/s/files/1/0437/8984/4641/files/60399809968.pdf
    • https://cdn.shopify.com/s/files/1/0434/1802/6142/files/bokotipowelize.pdf
    • https://cdn.shopify.com/s/files/1/0434/2244/9814/files/mimudol.pdf
    • https://cdn.shopify.com/s/files/1/0427/8288/4006/files/zaxuvamiberuwin.pdf
    • https://cdn.shopify.com/s/files/1/0433/5586/5242/files/vevowerugepazipefukajaxuk.pdf
    • https://cdn.shopify.com/s/files/1/0433/2004/9822/files/41661458427.pdf
    • https://cdn.shopify.com/s/files/1/0432/8790/4411/files/92805271637.pdf
    • https://cdn.shopify.com/s/files/1/0430/7202/8823/files/samayik_prasanga_bengali_newspaper_download.pdf
    • https://cdn.shopify.com/s/files/1/0435/5771/6117/files/51807663257.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005502.bin
b7c780a62e60e5a05d43ce8f70f20fbe8ea127715c5dce1fc9f513c8bd853d2e
pdf-font-stream PDF embedded font (sfnt) at offset 0x5502 4876 bytes
font_01_sfnt_off000065a4.bin
146e3a6636375de279708be0fa8fbe690b47f9dd4a987a0ad3e95b878a219f24
pdf-font-stream PDF embedded font (sfnt) at offset 0x65A4 10772 bytes