Malicious PDF — malware analysis report

Static analysis result for SHA-256 424321ef2fb34279…

MALICIOUS

PDF

34.9 KB Created: 2020-08-18 13:12:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7675415512f36d6d1f9ed9fdaca84384 SHA-1: a1ec97440e42f45f1715952eaad29dce7876879c SHA-256: 424321ef2fb34279a37b23d4763f6376f059a6feb70d27d68292a1dc6172adf2
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains numerous embedded links, a technique often used for SEO poisoning or to redirect users to malicious sites. The heuristic PDF_MALICIOUS_REDIRECTOR_LINK specifically flags a link to 'ttraff.ru', indicating malicious redirector infrastructure. The document body text, though partially corrupted, contains keywords like 'ambarsariya full movie mp4moviez' which serve as lures to entice users to click the embedded links, likely for phishing or malware distribution.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=ambarsariya+full+movie++mp4moviez
    • http://files.familyanimalcare.com/uploads/1/3/0/7/130776826/susumoxixanu-telonubike-zubisijeke.pdf
    • http://xivek.mastergardenersmecklenburg.org/uploads/1/3/1/4/131453046/vobesuparu.pdf
    • https://cdn.shopify.com/s/files/1/0429/8568/5153/files/rewulepi.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/dubisetebezurazoxodo.pdf
    • https://cdn.shopify.com/s/files/1/0427/6027/4087/files/65389960919.pdf
    • https://cdn.shopify.com/s/files/1/0433/9014/0581/files/akcent_songs_free_mp4.pdf
    • https://cdn.shopify.com/s/files/1/0432/8803/5486/files/ridobaled.pdf
    • https://cdn.shopify.com/s/files/1/0436/0588/5090/files/nedivozowapamamaronu.pdf
    • https://cdn.shopify.com/s/files/1/0436/8993/5002/files/academic_skills_for_interdisciplinary_studies.pdf
    • https://cdn.shopify.com/s/files/1/0435/5280/0920/files/gitufifuxenekezokir.pdf
    • https://cdn.shopify.com/s/files/1/0427/4513/5260/files/datudiv.pdf
    • https://cdn.shopify.com/s/files/1/0433/7578/8184/files/80654134796.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000494f.bin
b00bb750a19173dd4972aed86a6ad7ac7b3e1a1a9a98bd8945fd901f6b4fc234
pdf-font-stream PDF embedded font (sfnt) at offset 0x494F 5476 bytes
font_01_sfnt_off00005bf3.bin
28e922e35cb8fd992d43c5bb6c7af53bf13579feb4017770ea5cb233c97db79b
pdf-font-stream PDF embedded font (sfnt) at offset 0x5BF3 10304 bytes