Malicious PDF — malware analysis report

Static analysis result for SHA-256 def42cbdc02df963…

MALICIOUS

PDF

95.1 KB Created: 2020-09-15 22:29:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fa1715d81c1c99fe86817cd34d465db4 SHA-1: 4a51b7b6e715582bcd6bfb07154d219f8a9ae826 SHA-256: def42cbdc02df963454f1b57db43f4bb5f316c2255a8ed75a3df8de17745d56b
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.001 Malicious Link T1059.001 PowerShell

The PDF file contains a lure for a 'Gta 4 mod menu' and embeds a link to a known malicious redirector. The heuristic PDF_MALICIOUS_REDIRECTOR_LINK confirms this, and the link points to ttraff.com. The PDF also contains a link farm, as indicated by the PDF_SEO_LINK_FARM heuristic, suggesting an attempt to distribute malicious content.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=gta+4+mod+menu+xbox+360+usb+no+jtag
    • https://cdn.shopify.com/s/files/1/0437/7739/2794/files/algebra_6th_grade_icse.pdf
    • https://cdn.shopify.com/s/files/1/0429/7192/2591/files/bujovesusixeruzob.pdf
    • https://cdn.shopify.com/s/files/1/0431/0489/5143/files/47613985242.pdf
    • https://cdn.shopify.com/s/files/1/0431/9700/5981/files/treino_calistenia_iniciante.pdf
    • https://cdn.shopify.com/s/files/1/0434/7671/3637/files/lanavagibi.pdf
    • https://cdn.shopify.com/s/files/1/0432/3452/5352/files/game_android_gratis_terbaik_online.pdf
    • https://static.usrfiles.com/ugd/e00bd3_c7deac41e4a74f688e27af045734346a.pdf
    • https://static.usrfiles.com/ugd/b8c837_946e224b9e224da3ba33e5d7e7495b8f.pdf
    • https://static.usrfiles.com/ugd/bc0b97_0a593ecfd5d44629ad4a99a2434ed033.pdf
    • https://static.usrfiles.com/ugd/cd1d52_4f5728663c9e41909e549868f11d4b70.pdf
    • https://static.usrfiles.com/ugd/d2cc1f_da4a34f60bba4c57b5ce3a78ddb1cb26.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dc06.bin
48ceb10ce84f46fbb34e69d780fd2e76522444303761f7b2d7d58db34f1bdbd2
pdf-font-stream PDF embedded font (sfnt) at offset 0xDC06 7576 bytes
font_01_sfnt_off0000f583.bin
7eed6c02e0b1278949f5510faa0656adb812e3029c84dd68b0c8888697f1e63f
pdf-font-stream PDF embedded font (sfnt) at offset 0xF583 5880 bytes
font_02_sfnt_off0001097b.bin
e34e59ddc8ba38317da5b478dfebe4832887abe597a118ea55ad84b2c9d0fea7
pdf-font-stream PDF embedded font (sfnt) at offset 0x1097B 9036 bytes
font_03_sfnt_off000122f1.bin
7d66b2e903d86d5f596a01ba78cabece81e8bc204646a0dcfa124a9564358ee1
pdf-font-stream PDF embedded font (sfnt) at offset 0x122F1 14072 bytes
font_04_sfnt_off00014fb7.bin
a0c46fc50bfd269399493525172b1e4d09a53ad1019d91a1f35c98607bb8699a
pdf-font-stream PDF embedded font (sfnt) at offset 0x14FB7 19320 bytes