Malicious PDF — malware analysis report

Static analysis result for SHA-256 d85cec15e4568cfb…

MALICIOUS

PDF

42.1 KB Created: 2020-08-22 07:12:46 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3ae350c4fc8d202247cdeb03eb30218d SHA-1: df7226520be859959651f0f55091ab33b7966fd5 SHA-256: d85cec15e4568cfbb8259b8c1dd9471a297b37fd5bd94de87bdd09bf3d85abab
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a link to a known malicious redirector, ttraff.com, which is designed to lead users to further malicious content. The document body, though heavily obfuscated, contains the text 'App answer phone call' and the malicious URL, suggesting a lure to trick users into clicking the link. The presence of numerous external PDF links, many pointing to Shopify, indicates a link farm strategy to potentially improve SEO for malicious content or to distribute payloads.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=app+answer+phone+call
    • http://baxesiz.toharlev.com/uploads/1/3/1/4/131438641/nuxawuve.pdf
    • http://tumifone.poodlepets.com/uploads/1/3/0/7/130775565/namojiluzefiv.pdf
    • http://files.reesestocks.com/uploads/1/3/0/7/130738841/kakili-gijuf-bigux-gifuniluduj.pdf
    • https://cdn.shopify.com/s/files/1/0437/8247/1837/files/80319631760.pdf
    • https://cdn.shopify.com/s/files/1/0430/3850/7169/files/converting_metric_units_length_sheet_1_answers.pdf
    • https://cdn.shopify.com/s/files/1/0431/8658/5759/files/calorimetry_answers.pdf
    • https://cdn.shopify.com/s/files/1/0429/6772/8281/files/23023143226.pdf
    • https://cdn.shopify.com/s/files/1/0434/9529/3094/files/85902939856.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/pagujusevidunevaf.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/tebagomi.pdf
    • https://cdn.shopify.com/s/files/1/0436/7079/8489/files/52871629891.pdf
    • https://cdn.shopify.com/s/files/1/0434/4017/7314/files/nowudubulixifinujixenuv.pdf
    • https://cdn.shopify.com/s/files/1/0436/9465/3595/files/upsc_cds_1_2020_question_paper.pdf
    • https://cdn.shopify.com/s/files/1/0430/6577/0135/files/fagovupifuvabupod.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/ginowojero.pdf
    • https://cdn.shopify.com/s/files/1/0434/9739/0244/files/34174420489.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000067d3.bin
9dd84bbebb1da6eea0372ada7cd360e862d2669375e186c91c50b5c0e461e532
pdf-font-stream PDF embedded font (sfnt) at offset 0x67D3 5104 bytes
font_01_sfnt_off0000792d.bin
b6ae6d3d6ff7e5bf55e2e21ff5f068d47e970144bd3b8310a73005b412aa6900
pdf-font-stream PDF embedded font (sfnt) at offset 0x792D 9916 bytes