Malicious PDF — malware analysis report

Static analysis result for SHA-256 e7e2e3003e84fd1f…

MALICIOUS

PDF

43.4 KB Created: 2020-08-01 13:19:40 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3e83f9f1b3dcaa3e8ad087f4a43a78c4 SHA-1: 9b29c1ebbe0bb019d7b2a8b2559b73774baff8c4 SHA-256: e7e2e3003e84fd1fa72bbb48a84f05a1c8d4117fb19fec5e004d84f1e92dcab3
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a critical heuristic firing for a malicious redirector link pointing to 'https://ttraff.com/pify?keyword=platinum+disco+mp3'. Additionally, it exhibits a PDF link farm with 17 external PDF links, many hosted on cdn.shopify.com, suggesting an attempt to obscure the malicious destination or distribute further content. The document body contains the same redirector URL and a list of other PDF links, reinforcing the lure.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=platinum+disco+mp3
    • http://files.heritagemaplefarm.com/uploads/1/3/0/8/130873718/nazelulakof.pdf
    • http://files.amossoma.com/uploads/1/3/0/7/130775977/kefixugawekan.pdf
    • http://files.jeffreyscottsalsbury.com/uploads/1/3/0/7/130775698/4309229.pdf
    • http://files.homeopathhealer.com/uploads/1/3/0/7/130740183/pesifo_pekokelom_dosifoguzolix.pdf
    • https://cdn.shopify.com/s/files/1/0430/8484/1124/files/15854710346.pdf
    • https://cdn.shopify.com/s/files/1/0430/3791/7345/files/2791866467.pdf
    • https://cdn.shopify.com/s/files/1/0438/3988/1373/files/towad.pdf
    • https://cdn.shopify.com/s/files/1/0435/0076/5336/files/wuvimupevuvuvenanal.pdf
    • https://cdn.shopify.com/s/files/1/0438/8726/3899/files/dawovalelizevin.pdf
    • https://cdn.shopify.com/s/files/1/0437/5491/3950/files/list_of_pokemon_by_type.pdf
    • https://cdn.shopify.com/s/files/1/0427/7298/8071/files/voximukifidokajokomafuvo.pdf
    • https://cdn.shopify.com/s/files/1/0433/8132/5978/files/xuzel.pdf
    • https://cdn.shopify.com/s/files/1/0432/2502/2621/files/36264734719.pdf
    • https://cdn.shopify.com/s/files/1/0435/4048/0164/files/61004683002.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/2283550224.pdf
    • https://cdn.shopify.com/s/files/1/0429/7916/4314/files/82223332940.pdf
    • https://cdn.shopify.com/s/files/1/0436/9242/5384/files/malitipibajoje.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004ff5.bin
385c6cc2ca0533430f33dbe0fc5c2e432acb08f197b79b5f7df2e03b357e15e6
pdf-font-stream PDF embedded font (sfnt) at offset 0x4FF5 3680 bytes
font_01_sfnt_off00005d09.bin
fe5cf4762fc801fefb1892d85a05a1f2400635893afe8b3f0b6fe912582ecb7a
pdf-font-stream PDF embedded font (sfnt) at offset 0x5D09 5052 bytes
font_02_sfnt_off00006e11.bin
13f95bfc71cf1d87ed6dfa9d40be65ed8fa8a394405cbf40dc4ab0770f30fdd1
pdf-font-stream PDF embedded font (sfnt) at offset 0x6E11 10164 bytes
font_03_sfnt_off000090ca.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0x90CA 4324 bytes