Malicious PDF — malware analysis report

Static analysis result for SHA-256 1c57c67687b171a9…

MALICIOUS

PDF

48.2 KB Created: 2020-08-22 19:08:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 809f6728bade2657c66a6bbc569fa318 SHA-1: 25e4166675a16eacdb5b76da2246adce757e0cea SHA-256: 1c57c67687b171a9b50df8efa1b1ec6b667f57f88dcd6d6c44ec5a018b5b3f25
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains multiple embedded links, with one pointing to a known malicious redirector at 'ttraff.ru'. The document body, though heavily obfuscated, contains text related to 'adverbs of frequency' and the malicious URL, suggesting a lure to disguise the malicious intent. The presence of numerous links to Shopify-hosted PDFs indicates a link farm strategy, likely to improve search engine ranking and distribute malicious content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=adverbs+of+frequency+esl+pdf
    • http://files.maggiecjohnson.com/uploads/1/3/2/7/132740584/0cd5836ebbc316.pdf
    • http://vumexuru.wellaromanaturals.com/uploads/1/3/1/3/131380550/80be1.pdf
    • http://vapigupi.saintgregorysileby.org/uploads/1/3/1/3/131380934/kotebogisarisaf-folijoma-rojugizaj.pdf
    • http://files.griselda.com/uploads/1/3/2/7/132710603/c788995.pdf
    • https://cdn.shopify.com/s/files/1/0441/1555/8552/files/xiraxakulofevav.pdf
    • https://cdn.shopify.com/s/files/1/0439/2140/8168/files/lubovunijebirosu.pdf
    • https://cdn.shopify.com/s/files/1/0430/8143/3242/files/54994993397.pdf
    • https://cdn.shopify.com/s/files/1/0432/1997/6350/files/how_does_renin_angiotensin_system_regulate_blood_pressure.pdf
    • https://cdn.shopify.com/s/files/1/0438/8575/6568/files/morality_as_anti_nature.pdf
    • https://cdn.shopify.com/s/files/1/0428/3020/0991/files/zafinun.pdf
    • https://cdn.shopify.com/s/files/1/0430/9932/4567/files/zivokar.pdf
    • https://cdn.shopify.com/s/files/1/0434/4309/3670/files/ielts_academic_listening_samples_with_answers.pdf
    • https://cdn.shopify.com/s/files/1/0430/1992/7713/files/lajiluvumadabokubev.pdf
    • https://cdn.shopify.com/s/files/1/0429/9377/8837/files/67641498938.pdf
    • https://cdn.shopify.com/s/files/1/0428/7417/5644/files/zarorafelin.pdf
    • https://cdn.shopify.com/s/files/1/0431/5650/4744/files/bubepaz.pdf
    • https://cdn.shopify.com/s/files/1/0428/6880/1702/files/53139796953.pdf
    • https://cdn.shopify.com/s/files/1/0440/5755/9190/files/business_risk_definition.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/84407481133.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com/s/files

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007131.bin
e68174c7ee6edcb27236ba983343ba3e2fcf903d99295503ee70c64caf12c74e
pdf-font-stream PDF embedded font (sfnt) at offset 0x7131 5112 bytes
font_01_sfnt_off0000829b.bin
b7f0676a9eb520192ea009b28ef3a66f5f09232d52343658f2f392cbbdfb5459
pdf-font-stream PDF embedded font (sfnt) at offset 0x829B 10348 bytes
font_02_sfnt_off0000a5d6.bin
9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2
pdf-font-stream PDF embedded font (sfnt) at offset 0xA5D6 4324 bytes