Malicious PDF — malware analysis report

Static analysis result for SHA-256 2f42394b3ae276b3…

MALICIOUS

PDF

41.9 KB Created: 2020-08-23 07:38:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 69da187320879abe206dda8e422e89c7 SHA-1: a7c26428dc3edfa8a8a3b3bab50ef6db95e095c9 SHA-256: 2f42394b3ae276b3a6d3b172f834228b804e3f40bf1f8b87a52c5ad24192c266
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link to a known malicious redirector, ttraff.ru, which is disguised as a consent form. The document also exhibits characteristics of a link farm, with numerous embedded URLs pointing to external PDF files, likely to manipulate search engine results or distribute further malicious content. No scripts were extracted from this sample, but the presence of the malicious redirector and the link farm structure strongly suggest a phishing or content-distribution attack pattern.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=cibil+and+bgv+consent+form
    • http://bidumako.revfrankmcfadden.com/uploads/1/3/1/4/131453872/fae684c3e1098.pdf
    • https://cdn.shopify.com/s/files/1/0436/4979/4213/files/50245656810.pdf
    • https://cdn.shopify.com/s/files/1/0427/6341/9815/files/vugakifivebusosofi.pdf
    • https://cdn.shopify.com/s/files/1/0435/2363/7402/files/internet_manager_crack_full_version_myanmar.pdf
    • https://cdn.shopify.com/s/files/1/0436/3422/9401/files/72729868302.pdf
    • https://cdn.shopify.com/s/files/1/0427/6027/4087/files/58897561292.pdf
    • https://cdn.shopify.com/s/files/1/0431/9690/7684/files/cancion_del_mariachi_piano_sheet_music.pdf
    • https://cdn.shopify.com/s/files/1/0430/7006/2754/files/walej.pdf
    • https://cdn.shopify.com/s/files/1/0437/3407/3505/files/mexuberi.pdf
    • https://cdn.shopify.com/s/files/1/0435/5942/0063/files/arturia_minibrute_manual.pdf
    • https://cdn.shopify.com/s/files/1/0436/1004/6621/files/antony_and_cleopatra_script.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005856.bin
2e423279732a1c7cf85a344abf7109882d1f535f1a7fb75179dcea1ef1a30d7c
pdf-font-stream PDF embedded font (sfnt) at offset 0x5856 5352 bytes
font_01_sfnt_off00006a73.bin
b8a6a25999331f82cba79429080b07f6d296beaf2d3b59a46fa3502b15770f4a
pdf-font-stream PDF embedded font (sfnt) at offset 0x6A73 10128 bytes
font_02_sfnt_off00008d11.bin
ce7e2e230a41ba6fc2d7d2240890c8289d67876d84a3d076d67c0b48111c8230
pdf-font-stream PDF embedded font (sfnt) at offset 0x8D11 4324 bytes