Malicious PDF — malware analysis report

Static analysis result for SHA-256 f61a48641cdabea2…

MALICIOUS

PDF

44.3 KB Created: 2020-10-17 16:03:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 54bb43f547ed20f27cb1ccf061204ae1 SHA-1: 5bae60cdeb341973ec3d297c62492c5b710fc7de SHA-256: f61a48641cdabea207b611ea9331bd57caf77e4263fe2c4d48ea7d848eae7b71
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, which is also present in the document body. This link, 'https://ttraff.me/123?keyword=pdf+converter+premium+mod+apk', is likely intended to lead users to a malicious download. The presence of a 'SE_DOWNLOAD_BUTTON' heuristic further supports the lure-based attack pattern.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/123?keyword=pdf+converter+premium+mod+apk
    • https://cdn-cms.f-static.net/uploads/4375507/normal_5f8aad9ecc10e.pdf
    • https://cdn-cms.f-static.net/uploads/4366389/normal_5f874337688b0.pdf
    • https://cdn-cms.f-static.net/uploads/4365525/normal_5f8a6ecbd7145.pdf
    • https://cdn-cms.f-static.net/uploads/4370529/normal_5f88263f7511b.pdf
    • https://cdn-cms.f-static.net/uploads/4369665/normal_5f89aaa956c55.pdf
    • https://cdn-cms.f-static.net/upload
    • https://cdn.shopify.com/s/files/1/0502/9462/0333/files/73063715235.pdf
    • https://cdn.shopify.com/s/files/1/0440/7322/2294/files/camera_color_picker_android_github.pdf
    • https://cdn.shopify.com/s/files/1/0483/9233/9614/files/suunto_ambit3_sport_hr_manual.pdf
    • https://cdn.shopify.com/s/files/1/0497/6050/1921/files/jerabaxexos.pdf
    • https://uploads.strikinglycdn.com/files/a04b0ab4-2803-4287-8800-d5a4dee5b1cb/56354462667.pdf
    • https://uploads.strikinglycdn.com/files/3e8701da-95ed-4ff6-a07d-9a73ceee7f4c/54926465854.pdf
    • https://uploads.strikinglycdn.com/files/f741ac13-df41-4c56-b7f0-fa7d6c66bad5/buzuforazebitazifivaxu.pdf
    • https://uploads.strikinglycdn.com/files/f1f21c6f-5166-4396-8d97-667c41669adc/paragu.pdf
    • https://uploads.strikinglycdn.com/files/54eef1e1-ca5c-4ca1-8c98-b0b614fe2b63/bolefedigetagu.pdf
    • https://cdn.shopify.com/s/files/1/0433/8856/7706/files/golden_retriever_red_puppies.pdf
    • https://cdn.shopify.com/s/files/1/0430/5187/6509/files/93958943802.pdf
    • https://cdn.shopify.com/s/files/1/0434/4584/6168/files/modern_database_management_11th.pdf
    • https://cdn.shopify.com/s/files/1/0480/0020/4959/files/22787417675.pdf
    • https://cdn.shopify.com/s/files/1/0440/8085/7253/files/xinekebak.pdf
    • https://cdn.shopify.com/s/files/1/0428/8361/2831/files/unblocked_games_games.pdf
    • https://cdn.shopify.com/s/files/1/0497/3776/0917/files/govezaj.pdf
    • https://cdn.shopify.com/s/files/1/0502/3019/8444/files/89457088680.pdf
    • https://cdn.shopify.com/s/files/1/0493/4762/5119/files/khmer_movies_drama.pdf
    • https://cdn.shopify.com/s/files/1/0435/0282/9734/files/20654609510.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006f88.bin
09f50cdbfe398785cde579668e12917f17b0560540a9a97aff316d81745af184
pdf-font-stream PDF embedded font (sfnt) at offset 0x6F88 5216 bytes
font_01_sfnt_off00008138.bin
f6df9cfc26373a8f16c791cd15fa6cc848b62a8ec70238b5a4ae13fd73b72b46
pdf-font-stream PDF embedded font (sfnt) at offset 0x8138 10028 bytes