Malicious PDF — malware analysis report

Static analysis result for SHA-256 3ce1fea2a4277d0c…

MALICIOUS

PDF

35.9 KB Created: 2020-08-22 10:22:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 811af5740ba520d039fffa11d6a5b0ed SHA-1: 4bbc94ef184995bd804a0a4af7f749645eb3ed84 SHA-256: 3ce1fea2a4277d0cc2a8077400bf60c3c6061cfc991264340cc5f9faf3e99016
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a malicious redirector link, specifically pointing to 'ttraff.ru'. The document body, though heavily obfuscated, also contains this URL, suggesting it's the primary lure. The file also exhibits characteristics of a link farm, with numerous embedded URLs, many hosted on Shopify, but one critical link directs to malicious infrastructure. No scripts were extracted, and the PDF structure itself does not indicate exploitation, but rather social engineering via embedded links.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=forrest+gump+main+theme+piano+sheet
    • http://files.panisangelicuspress.com/uploads/1/3/1/3/131384018/7094245.pdf
    • http://files.dreamchen.org/uploads/1/3/1/3/131384636/nubadobode.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/86399573169.pdf
    • https://cdn.shopify.com/s/files/1/0432/0873/6928/files/unclaimed_property_new_jersey_reporting.pdf
    • https://cdn.shopify.com/s/files/1/0432/8967/3883/files/72890386434.pdf
    • https://cdn.shopify.com/s/files/1/0435/3218/9860/files/30188035916.pdf
    • https://cdn.shopify.com/s/files/1/0436/8800/1689/files/tulotufebemegom.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/44603331863.pdf
    • https://cdn.shopify.com/s/files/1/0432/7132/3804/files/support_vector_machine.pdf
    • https://cdn.shopify.com/s/files/1/0433/9928/2845/files/aufklrung_epoche_literatur.pdf
    • https://cdn.shopify.com/s/files/1/0432/4383/1464/files/bedokelak.pdf
    • https://cdn.shopify.com/s/files/1/0433/1926/3397/files/how_can_you_answer_interview_question.pdf
    • https://cdn.shopify.com/s/files/1/0434/4312/6438/files/mazebo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000041a2.bin
9a6ccf734e797adffdba73cc39c9e2df324b3eb3cbebde9b1b700f33122cb78b
pdf-font-stream PDF embedded font (sfnt) at offset 0x41A2 5040 bytes
font_01_sfnt_off00005296.bin
aa1bc71ef516360feeae09e30cdf60f10c2f902d3f71ad149edb8c9c161d59e2
pdf-font-stream PDF embedded font (sfnt) at offset 0x5296 10220 bytes
font_02_sfnt_off000074f6.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x74F6 4324 bytes