Malicious PDF — malware analysis report

Static analysis result for SHA-256 31f994eb94a9363b…

MALICIOUS

PDF

34.4 KB Created: 2020-08-30 17:46:53 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7fb818aee6e1c7336e26cbc542f5e81a SHA-1: 5cb6d5f0cf8c32aacda2b6ba191d960032a79915 SHA-256: 31f994eb94a9363bba403426c35d27cf9458cd4411186de97a2c8ca9a1a19e68
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.ru/wix?keyword=earth+science+the+physical+setting+answer+key+2015'. This URL is presented within the document body, disguised as a link to an answer key. The PDF also contains a mass external PDF link farm, with many links pointing to static.usrfiles.com. The overall purpose appears to be social engineering users into clicking the malicious link.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=earth+science+the+physical+setting+answer+key+2015
    • https://static.usrfiles.com/ugd/0cd3a8_83b08870f7694a728f06b4bb225fdb97.pdf
    • https://static.usrfiles.com/ugd/cf14a4_16fbc76fb5114670b423b449124486f5.pdf
    • https://static.usrfiles.com/ugd/b8c837_a1e595c142fe4d1aa22bfba95c315d95.pdf
    • https://static.usrfiles.com/ugd/162fe6_21f86d473b4c4eb2bc44e393190036b3.pdf
    • https://static.usrfiles.com/ugd/934fc3_7d94ba1461d34b2c8383f372b98f5d40.pdf
    • https://static.usrfiles.com/ugd/b8c837_4a12b8c2a6b14c78b162a8183953af0f.pdf
    • https://static.usrfiles.com/ugd/b8c837_7f2fee6cbd634393875379cf7b6b5e53.pdf
    • https://static.usrfiles.com/ugd/b8c837_7471b1917eb94287b999ede0c3e7c742.pdf
    • https://static.usrfiles.com/ugd/5d2cf3_ed3b0aef96134ddda0f0e93226203db1.pdf
    • https://static.usrfiles.com/ugd/b8c837_d848dcfe411946d194bb6a3471ffe9de.pdf
    • https://static.usrfiles.com/ugd/6908d7_e6b77af9116542b7a1855e6bf16e1e03.pdf
    • https://cdn.shopify.com/s/files/1/0433/0985/8984/files/zaxilivedalatimugexuzo.pdf
    • https://cdn.shopify.com/s/files/1/0431/0233/9232/files/90390284053.pdf
    • https://cdn.shopify.com/s/files/1/0432/6467/1909/files/setubifovimizil.pdf
    • https://cdn.shopify.com/s/files/1/0435/2425/9992/files/76260547636.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000043bf.bin
d3f7dc5ea3ece350555781b68173ab156fdd5b6f7a7399132fc60e70e8575e75
pdf-font-stream PDF embedded font (sfnt) at offset 0x43BF 5860 bytes
font_01_sfnt_off000057d0.bin
1faf4d1820a6c4972dcd32ef31e4e9c01ea4e8227a8cf757fdb2d022bbf0ddec
pdf-font-stream PDF embedded font (sfnt) at offset 0x57D0 11240 bytes