Malicious PDF — malware analysis report

Static analysis result for SHA-256 37102b94434da097…

MALICIOUS

PDF

42.0 KB Created: 2020-09-02 10:24:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 76c5e4504ea4ddc140c3ef30f8ca7366 SHA-1: ab44cdb3fc55e9e3ea281cca4824bcb60da2e6f6 SHA-256: 37102b94434da097d2f4fe0c709165cae8afa2251e116f0f2bfc1a8e3e538c5d
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a link farm and a direct link to a known malicious redirector, disguised as a worksheet. The primary malicious URL is https://ttraff.ru/wix?keyword=plotting+points+on+coordinate+plane+worksheet+pdf, which likely leads to further malicious content. The document body, though heavily obfuscated, contains this URL and references to other PDFs hosted on static.usrfiles.com, indicating a redirection or download attempt.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=plotting+points+on+coordinate+plane+worksheet+pdf
    • https://static.usrfiles.com/ugd/b8c837_3107dfe9b730412ba74a3e62a761ee0c.pdf
    • https://static.usrfiles.com/ugd/dcbeda_bc2c06896b724587b843f4d263f3a42f.pdf
    • https://static.usrfiles.com/ugd/370b54_b003020b39cd4a2eb323e91b5db6a575.pdf
    • https://static.usrfiles.com/ugd/ceb2e8_d7716a47dd314d78a68405c3e8e29be2.pdf
    • https://static.usrfiles.com/ugd/6908d7_d4f74f29bf6248b2a40c44e73047cd47.pdf
    • https://cdn.shopify.com/s/files/1/0438/8922/9979/files/semasovigafeduge.pdf
    • https://cdn.shopify.com/s/files/1/0437/2178/5498/files/78838251681.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/sexewagufik.pdf
    • https://cdn.shopify.com/s/files/1/0434/0786/8060/files/58115465979.pdf
    • https://cdn.shopify.com/s/files/1/0438/8261/0843/files/asp._net_page_life_cycle.pdf
    • https://cdn.shopify.com/s/files/1/0432/1234/1409/files/azurescens_grow_guide.pdf
    • https://static.usrfiles.com/ugd/b8c837_f74a5a5cb2074ed6869c334f141b7749.pdf
    • https://static.usrfiles.com/ugd/b8c837_549c9876e97844ce934c9dd34441b7b0.pdf
    • https://static.usrfiles.com/ugd/0e9fc2_ce6b05659cd140179d0b530f54eba4e0.pdf
    • https://static.usrfiles.com/ugd/6290de_51d67bf0452d49eaa8b585b34939e5f6.pdf
    • https://static.usrfiles.com/ugd/83b1b3_a3e56f971a7b4aee9ab35470eb5169c4.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006615.bin
2c5bd2bf7bc6f7a9f2333c3a8847758b8db646b26aa75a4d51758a8130228485
pdf-font-stream PDF embedded font (sfnt) at offset 0x6615 5576 bytes
font_01_sfnt_off0000791d.bin
96f08bb3f774dac147d0cf4bfc21458dd2c247529645e925ee8f6e321c3c9830
pdf-font-stream PDF embedded font (sfnt) at offset 0x791D 9856 bytes