Malicious PDF — malware analysis report

Static analysis result for SHA-256 2123d3f8bdec36b8…

MALICIOUS

PDF

44.5 KB Created: 2020-08-20 02:11:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 705940286e4137a6570f757f25dfd31c SHA-1: 21132c968c796ec23b52ff51e3423625682fda2b SHA-256: 2123d3f8bdec36b80ece4a0419429d9558e3acb6678a78dac064f730642c4626
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

This PDF document contains a large number of external links, many of which point to Shopify domains, suggesting a link farm for SEO manipulation. One prominent link, "https://ttraff.ru/pify?keyword=manualidades+muy+faciles+para+vender", is identified as a malicious redirector. The document body, though heavily obfuscated, contains this URL and other Shopify URLs, indicating a likely attempt to drive traffic to malicious infrastructure under the guise of providing resources related to "manualidades muy faciles para vender". No scripts were extracted, limiting the analysis of direct payload execution.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=manualidades+muy+faciles+para+vender
    • http://files.isenterprises.net/uploads/1/3/1/4/131455463/5289298.pdf
    • http://gevufape.fleischerstudios.com/uploads/1/3/2/6/132680981/ruxomu.pdf
    • http://files.stonecutterswsq.com/uploads/1/3/1/4/131406222/377363.pdf
    • https://cdn.shopify.com/s/files/1/0432/7574/7491/files/piano_sheet_music_book_free.pdf
    • https://cdn.shopify.com/s/files/1/0438/2638/0960/files/bricks_breaker_quest_apk.pdf
    • https://cdn.shopify.com/s/files/1/0429/9387/7145/files/caring_for_rabbits.pdf
    • https://cdn.shopify.com/s/files/1/0431/9812/0094/files/bonofanemilimupanog.pdf
    • https://cdn.shopify.com/s/files/1/0447/5607/4645/files/former_employee_meaning_in_tamil.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/rinubigelezegir.pdf
    • https://cdn.shopify.com/s/files/1/0432/8429/9936/files/guwuzakebavuw.pdf
    • https://cdn.shopify.com/s/files/1/0428/0962/2691/files/1425894273.pdf
    • https://cdn.shopify.com/s/files/1/0439/8913/9614/files/87497452655.pdf
    • https://cdn.shopify.com/s/files/1/0430/2857/8467/files/currency_risk_definition.pdf
    • https://cdn.shopify.com/s/files/1/0433/2643/9582/files/cabala_hermtica.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006b75.bin
ca48902fa21a65f255b6aeaabf170cfc9a0e05d2e9501419aca0988d7e98fe9c
pdf-font-stream PDF embedded font (sfnt) at offset 0x6B75 5468 bytes
font_01_sfnt_off00007e06.bin
ecf8c3f678b55677efb0db2bc93e6eae4c1f44cdb59e0a29e5f04c0202035c1f
pdf-font-stream PDF embedded font (sfnt) at offset 0x7E06 11508 bytes