Malicious PDF — malware analysis report

Static analysis result for SHA-256 d8a4435529e7cfec…

MALICIOUS

PDF

63.3 KB Created: 2020-08-09 00:33:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 53af9ad1abdda5bab8d04af20adb1dc3 SHA-1: a0eed67c7f2a140e726d7b293841c59d302ff7ff SHA-256: d8a4435529e7cfec5ff71c545afa093f36520065c48bdd0bdeb294222cacc368
140 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1566.002 Spearphishing Attachment

The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'ttraff.com'. Additionally, it exhibits a PDF link farm heuristic and impersonates a cloud document lure. The embedded URL in the document body, 'https://ttraff.com/pify?keyword=collins+vocabulary+for+ielts+pdf+audio+pre+intermediate', is the primary indicator of malicious intent, likely leading to further compromise.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Cloud document impersonation lure medium SE_CLOUD_DOC_LURE
    Document impersonates a cloud file-sharing service such as SharePoint, OneDrive, Google Drive, Dropbox, Box, or Microsoft 365 and asks the user to open, verify, or access a shared document
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=collins+vocabulary+for+ielts+pdf+audio+pre+intermediate
    • http://files.exmouthcaninecentre.co.uk/uploads/1/3/0/8/130874128/jenasaj.pdf
    • http://files.bydesignholistichealth.com/uploads/1/3/1/3/131380263/f90a8d52.pdf
    • http://files.msmillyard.com/uploads/1/3/1/1/131164479/jasolugoza.pdf
    • http://files.transworldgeneralcommerce.com/uploads/1/3/2/7/132710779/zugefememom.pdf
    • http://files.kamariawilliams.com/uploads/1/3/1/4/131482884/nigowopufusetap-jotekiwamufa.pdf
    • http://files.transworldgeneralcommerce.com/uploads/1/3/2/7
    • https://cdn.shopify.com/s/files/1/0450/4194/2678/files/a_guide_to_rational_living.pdf
    • https://cdn.shopify.com/s/files/1/0429/9928/3863/files/71771805125.pdf
    • https://cdn.shopify.com/s/files/1/0437/2905/9989/files/cestina_express_1_download.pdf
    • https://cdn.shopify.com/s/files/1/0434/3064/1829/files/bijodi.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/xewujixamugovaginebutomo.pdf
    • https://cdn.shopify.com/s/files/1/0432/2571/0750/files/bijuxaruwesudoluwixafiga.pdf
    • https://cdn.shopify.com/s/files/1/0431/3242/0264/files/benumof_s_airway_management_download.pdf
    • https://cdn.shopify.com/s/files/1/0428/7735/4143/files/supitixutefumoladil.pdf
    • https://cdn.shopify.com/s/files/1/0431/7492/0347/files/nowafiwifezeninozitev.pdf
    • https://cdn.shopify.com/s/files/1/0432/3485/3021/files/19175698670.pdf
    • https://cdn.shopify.com/s/files/1/0434/8923/1000/files/twinkle_twinkle_little_star_notes_piano.pdf
    • https://cdn.shopify.com/s/files/1/0441/2204/6616/files/multidimensional_array_in_php.pdf
    • https://cdn.shopify.com/s/files/1/0430/5630/0186/files/depaxuzugev.pdf
    • https://cdn.shopify.com/s/files/1/0439/0472/9243/files/kumibufi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008006.bin
001d49bce3aac1833e3634829e5c40c2fdbd77c84ef56eae0b5b4b9015cc162d
pdf-font-stream PDF embedded font (sfnt) at offset 0x8006 5508 bytes
font_01_sfnt_off000092ad.bin
9846ef34706657651cf08b0f10257735cf101a8b96348574ee2ba71eb18900b7
pdf-font-stream PDF embedded font (sfnt) at offset 0x92AD 9816 bytes
font_02_sfnt_off0000b2c0.bin
37cca7af90913ed4b01b14cbdcf785e3b5bd5f970e2b43292b5578d6925c1676
pdf-font-stream PDF embedded font (sfnt) at offset 0xB2C0 11128 bytes
font_03_sfnt_off0000d8d3.bin
59df8ef4094dca04bfdb32b75afd63795d8fb3142a6ac62c139ff08232403af2
pdf-font-stream PDF embedded font (sfnt) at offset 0xD8D3 16256 bytes