Malicious PDF — malware analysis report

Static analysis result for SHA-256 d0798f2cbcc334a3…

MALICIOUS

PDF

85.0 KB Created: 2020-08-06 09:00:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fea4b2774ef5b4c49ba594e381bd6225 SHA-1: 5fab5a3408469ce7d4490cec465793fdaac13ba6 SHA-256: d0798f2cbcc334a31a0ed09fba428002d39815e0ea9f0e1ba6c5e4b0dae76f72
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains multiple embedded URLs, with a critical heuristic firing indicating a malicious redirector link to 'https://ttraff.com/pify?keyword=abbreviations+in+computer+networks+pdf'. Another critical heuristic identified a PDF link farm, suggesting the document's primary purpose is to distribute links to other PDFs, likely for SEO manipulation or to host further malicious content. The document body text, though partially corrupted, includes the same URL, reinforcing the malicious intent.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=abbreviations+in+computer+networks+pdf
    • http://files.pilatesdonewright.com/uploads/1/3/0/8/130873932/8250716.pdf
    • http://files.lillymholland.com/uploads/1/3/1/4/131437683/7bd370c.pdf
    • http://jewekinin.readwithmrsd.com/uploads/1/3/1/3/131379732/kuwani_tafenelu_kupor_jafulotizaminu.pdf
    • http://xavud.covcathcolonels.com/uploads/1/3/1/8/131857419/mubepinigekev-xovola.pdf
    • http://kaduka.globalcompassionday.com/uploads/1/3/0/8/130813612/e02a6d8cd305468.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/libutufisolefod.pdf
    • https://cdn.shopify.com/s/files/1/0438/8660/8552/files/latar_belakang_agama_buddha.pdf
    • https://cdn.shopify.com/s/files/1/0437/0402/5242/files/angielski_pacjent_chomikuj.pdf
    • https://cdn.shopify.com/s/files/1/0438/2438/2109/files/xuxelurakavitawelalivi.pdf
    • https://cdn.shopify.com/s/files/1/0435/9480/9507/files/votodi.pdf
    • https://cdn.shopify.com/s/files/1/0431/6643/3435/files/43469206411.pdf
    • https://cdn.shopify.com/s/files/1/0432/7433/8454/files/zarusanu.pdf
    • https://cdn.shopify.com/s/files/1/0427/9477/8791/files/50253334896.pdf
    • https://cdn.shopify.com/s/files/1/0437/7932/6110/files/vifavatisuxuso.pdf
    • https://cdn.shopify.com/s/files/1/0432/7797/5717/files/gasekijafiwixedezo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001025f.bin
5a871aa467178de7698953c89f165f43f82147636513384af53b66257a0499dd
pdf-font-stream PDF embedded font (sfnt) at offset 0x1025F 5616 bytes
font_01_sfnt_off0001157d.bin
466ecc20cef2dca0d8254cb07ea54a006a0d04374ac003bb45fdf48a456c283d
pdf-font-stream PDF embedded font (sfnt) at offset 0x1157D 15888 bytes