Malicious PDF — malware analysis report

Static analysis result for SHA-256 2a31f18a62084313…

MALICIOUS

PDF

36.5 KB Created: 2020-08-20 06:22:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7587e3553b6e7729da1fae77409c7252 SHA-1: 0cf2b14078bcb22a5a04d2e198520953af7d9c31 SHA-256: 2a31f18a620843137349f638dad079abed0e5302bb98f2a73099cd1db073f5a2
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1200 Hardware Add-in T1059.001 PowerShell

The PDF file contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.ru/pify?keyword=crafting+guide+dayz'. Additionally, it exhibits characteristics of a PDF SEO link farm, embedding numerous links, many of which point to Shopify-hosted PDFs. The document body, though heavily obfuscated, contains the same suspicious URL and several Shopify URLs, reinforcing the lure. The primary intent appears to be redirecting users to malicious infrastructure under the guise of a crafting guide.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=crafting+guide+dayz
    • http://nixitojij.angelikabail.com/uploads/1/3/1/6/131636755/foxojirumulujisano.pdf
    • http://wufesoxog.greenhousewivesbathco.com/uploads/1/3/1/4/131410399/vawege.pdf
    • https://cdn.shopify.com/s/files/1/0431/7980/2782/files/3500482808.pdf
    • https://cdn.shopify.com/s/files/1/0433/7962/2040/files/92657725638.pdf
    • https://cdn.shopify.com/s/files/1/0435/8704/3496/files/affirmez_vous_fanget.pdf
    • https://cdn.shopify.com/s/files/1/0430/5554/6517/files/23887504894.pdf
    • https://cdn.shopify.com/s/files/1/0430/0950/7487/files/bebamejonevek.pdf
    • https://cdn.shopify.com/s/files/1/0432/1764/9819/files/80340204313.pdf
    • https://cdn.shopify.com/s/files/1/0432/9560/4891/files/ganug.pdf
    • https://cdn.shopify.com/s/files/1/0428/9580/2527/files/84630259866.pdf
    • https://cdn.shopify.com/s/files/1/0429/1044/9820/files/agile_scrum_board_template_excel.pdf
    • https://cdn.shopify.com/s/files/1/0432/8675/7536/files/ruvimurabofas.pdf
    • https://cdn.shopify.com/s/files/1/0429/5848/7703/files/regulation_of_amino_acid_metabolism.pdf
    • https://cdn.shopify.com/s/files/1/0446/5659/1011/files/161_bus_schedule_nj_transit.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000051b8.bin
24c773d9df2bc15e87b010882fcb47b4a53ee410ac2dcfbec0daf2586271de97
pdf-font-stream PDF embedded font (sfnt) at offset 0x51B8 4924 bytes
font_01_sfnt_off00006294.bin
115a3bda3dd018a559e4b7a71c73e390a092db96f7fbd2a4df1b7df61cac20eb
pdf-font-stream PDF embedded font (sfnt) at offset 0x6294 10236 bytes