Malicious PDF — malware analysis report

Static analysis result for SHA-256 f9d6521a4fe2879b…

MALICIOUS

PDF

42.7 KB Created: 2020-09-01 11:40:58 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 80ed639dd7f7b78ee67154ba5b223351 SHA-1: fc43afc81e856687d4dca17d8731ed5c142cbeb7 SHA-256: f9d6521a4fe2879ba49e3a1f91a8e26f69c7294b1a70098895091313df98b625
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, which points to `https://ttraff.cc/wix`. Additionally, it exhibits a PDF link farm heuristic, with numerous links pointing to benign Shopify domains, but one specific PDF link `https://cdn.shopify.com/s/files/1/0427/4061/3286/files/kipujonakupuxibetikigavup.pdf` is also listed as an IOC. The presence of a low-severity heuristic for a download button lure suggests a social engineering attempt. The document body contains garbled text but includes the malicious redirector URL and several benign Shopify URLs.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=doraemon+cartoon+free++for+mobile
    • https://cdn.shopify.com/s/files/1/0427/4061/3286/files/kipujonakupuxibetikigavup.pdf
    • https://cdn.shopify.com/s/files/1/0440/7522/1157/files/95754132213.pdf
    • https://cdn.shopify.com/s/files/1/0432/1764/9819/files/58146624598.pdf
    • https://cdn.shopify.com/s/files/1/0427/6623/7852/files/nupobe.pdf
    • https://cdn.shopify.com/s/files/1/0438/8293/8520/files/best_internet_booster_app_for_android_phone.pdf
    • https://cdn.shopify.com/s/files/1/0440/7413/9800/files/tobopoj.pdf
    • https://cdn.shopify.com/s/files/1/0431/6512/2720/files/xobuvufoxedebepatu.pdf
    • https://cdn.shopify.com/s/files/1/0440/8541/1990/files/hospital_administration_job_description.pdf
    • https://cdn.shopify.com/s/files/1/0430/0318/3258/files/all_in_one_toolbox_for_pc.pdf
    • https://static.usrfiles.com/ugd/fe83c3_415b39af771248b6b5ef706bce48c4fb.pdf
    • https://static.usrfiles.com/ugd/63022f_a1bdffad57804c9dabd93957b0f7d0d5.pdf
    • https://static.usrfiles.com/ugd/e2c6c1_1117c23214e84e33bb2c130d477ebe9c.pdf
    • https://static.usrfiles.com/ugd/b8c837_5a4bcb5b25d54fa685ba53a4e75da3a6.pdf
    • https://static.usrfiles.com/ugd/0c41e7_06dbfe6cd20041a1abb1750dfc8a0687.pdf
    • https://static.usrfiles.com/ugd/b8c837_74a5ce99115d458bb9fffb5bc40a766f.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005d5f.bin
43e7a7e17fb4113dd5eda4bc514a17e955495f80fb2100d8996ed096762b062c
pdf-font-stream PDF embedded font (sfnt) at offset 0x5D5F 4776 bytes
font_01_sfnt_off00006d7a.bin
b5d08d7b0e5623313f69bec0f049bd78efb2b7ac33953e75f4aa40a0331bbdda
pdf-font-stream PDF embedded font (sfnt) at offset 0x6D7A 10016 bytes
font_02_sfnt_off00008fd1.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0x8FD1 4324 bytes