Malicious PDF — malware analysis report

Static analysis result for SHA-256 31a72a83cc5ef8a9…

MALICIOUS

PDF

43.5 KB Created: 2020-08-12 11:45:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 70e2a62fc85c364101c61e752cc58904 SHA-1: 63a25e4f6db1e5405693b553016c739e5d3f4f2a SHA-256: 31a72a83cc5ef8a932abb7f5d7f95dbba98aad3a1f3d6c78e4b1e78a146c8538
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains multiple embedded URLs, with one identified as a malicious redirector. The heuristic PDF_MALICIOUS_REDIRECTOR_LINK specifically flags the URL https://ttraff.ru/wb?keyword=sayyid%20sabiq%20fiqh%20sunnah%20pdf as malicious. Additionally, the PDF_SEO_LINK_FARM heuristic indicates a large number of external PDF links, suggesting a link farm designed to manipulate search engine results or distribute further malicious content. The document body itself is heavily obfuscated but contains some of the URLs, reinforcing the redirection attempt.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wb?keyword=sayyid%20sabiq%20fiqh%20sunnah%20pdf
    • http://luzige.gentlepalmkarate.com/uploads/1/3/1/3/131383657/e33bc77caf897.pdf
    • http://files.mametcalfe.com/uploads/1/3/1/4/131411688/4c1a7dbfa8.pdf
    • http://files.uprowing.com/uploads/1/3/0/7/130775373/wifimixuj_gebadub_tobugibadonugi_wegiv.pdf
    • http://files.portsmouthrelayforlife.com/uploads/1/3/2/8/132814929/tugutixobexu_tizubivoxo.pdf
    • http://files.enigmashetlandponystud.com/uploads/1/3/1/4/131454521/janivuv.pdf
    • https://cdn.shopify.com/s/files/1/0433/1097/3083/files/sexozekevukunadorep.pdf
    • https://cdn.shopify.com/s/files/1/0429/7320/0537/files/avol_tv_website.pdf
    • https://cdn.shopify.com/s/files/1/0449/2450/2171/files/paramphistomum_cervi.pdf
    • https://cdn.shopify.com/s/files/1/0433/1179/2286/files/63738750303.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/25668779603.pdf
    • https://cdn.shopify.com/s/files/1/0434/3093/6733/files/10672680252.pdf
    • https://cdn.shopify.com/s/files/1/0437/7473/8581/files/dadisolinabadoxog.pdf
    • https://cdn.shopify.com/s/files/1/0436/6453/9798/files/brucellose_animale.pdf
    • https://cdn.shopify.com/s/files/1/0429/3686/0839/files/77651237464.pdf
    • https://cdn.shopify.com/s/files/1/0430/0147/9321/files/tuwumavavagozari.pdf
    • https://cdn.shopify.com/s/files/1/0428/3557/4943/files/xebubak.pdf
    • https://cdn.shopify.com/s/files/1/0433/7647/6311/files/29541447985.pdf
    • https://cdn.shopify.com/s/files/1/0431/1174/3639/files/what_does_enchanted_mean.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006bcd.bin
a9d9511568589060b1c7c60050cc1631b8b1a4581c6ecb0cf18258591e65071c
pdf-font-stream PDF embedded font (sfnt) at offset 0x6BCD 5472 bytes
font_01_sfnt_off00007e5e.bin
42165656394f438153b46e459e28531ef0510027b1ba219a6b7402a78434db43
pdf-font-stream PDF embedded font (sfnt) at offset 0x7E5E 10300 bytes