Malicious PDF — malware analysis report

Static analysis result for SHA-256 ddf4b4d34d3fe2b0…

MALICIOUS

PDF

35.4 KB Created: 2020-08-11 15:36:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 58b9ae7f258d041a7599bc8e4f3c2b4c SHA-1: 5931296d079f53c0e4ef24891d1101f1b31149b0 SHA-256: ddf4b4d34d3fe2b023fd7f645ccb00d14e3f62a69d83e12490721e8d1ecac776
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a large number of embedded links, many of which point to a link farm hosted on cdn.shopify.com. One critical heuristic identified a malicious redirector link to ttraff.com, which is likely used to funnel victims to further malicious content. The document body itself is heavily obfuscated but contains the same redirector URL and several other benign-looking PDF links. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=past+simple+exercises+complete+the+text+pdf
    • http://files.sophiemargolin.com/uploads/1/3/0/8/130874543/706eed6c.pdf
    • http://files.dopesickdotcom.com/uploads/1/3/1/0/131070011/3746615.pdf
    • http://komeda.bhsautomotive.com/uploads/1/3/1/4/131408899/kafosewaroked_soliza_xaruw.pdf
    • http://files.geneseecountymg.org/uploads/1/3/0/9/130969499/b226029de498.pdf
    • https://cdn.shopify.com/s/files/1/0436/1574/8253/files/water_level_sensor_arduino.pdf
    • https://cdn.shopify.com/s/files/1/0432/9409/7576/files/telecharger_carte_du_monde.pdf
    • https://cdn.shopify.com/s/files/1/0429/2381/9175/files/82734422606.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/8861538602.pdf
    • https://cdn.shopify.com/s/files/1/0429/7523/2153/files/gexafa.pdf
    • https://cdn.shopify.com/s/files/1/0438/2598/7734/files/best_fantasy_football_apps_2016.pdf
    • https://cdn.shopify.com/s/files/1/0428/3462/4679/files/latizonev.pdf
    • https://cdn.shopify.com/s/files/1/0437/4170/8453/files/network_marketing_business_plan.pdf
    • https://cdn.shopify.com/s/files/1/0432/7977/7952/files/puzavidalitalafemufet.pdf
    • https://cdn.shopify.com/s/files/1/0431/5712/7336/files/malaxojudowajugopaxuf.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/25346701784.pdf
    • https://cdn.shopify.com/s/files/1/0430/9961/9492/files/vukisumisopelanemuxezez.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004bca.bin
1c4d5b55cebe7d1d610536aa78c9cff14fc430d9c41297e9842b2e55dcad90d9
pdf-font-stream PDF embedded font (sfnt) at offset 0x4BCA 5464 bytes
font_01_sfnt_off00005e35.bin
70dec9bba6f7bdc5c85dc1c34f0a26e4202d62acaae6490444f0062e34fc5943
pdf-font-stream PDF embedded font (sfnt) at offset 0x5E35 10068 bytes