Malicious PDF — malware analysis report

Static analysis result for SHA-256 42712edcce6fc4d8…

MALICIOUS

PDF

47.5 KB Created: 2020-08-31 03:14:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 74ee958626f22d2b2f65624aa9f189d3 SHA-1: 96d4f00d47a7ecfa2dd7aab2f1b7b7d69e466c19 SHA-256: 42712edcce6fc4d88a16986f535c1b9e7f80ce5231e748b0dd6340e4174f3f41
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a significant number of embedded URLs, many pointing to external PDF files hosted on Shopify. This suggests a link farm or SEO poisoning tactic. One of the embedded URLs, https://ttraff.ru/wix?keyword=john+deere+ltr+166+parts, was identified as a malicious redirector. No scripts were extracted from this sample, and the document body is heavily obfuscated, limiting further analysis of the specific lure.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=john+deere+ltr+166+parts
    • https://cdn.shopify.com/s/files/1/0430/2353/2195/files/zisasegomiwegin.pdf
    • https://cdn.shopify.com/s/files/1/0438/2644/6496/files/cepacaina_spray_bula.pdf
    • https://cdn.shopify.com/s/files/1/0441/1867/1512/files/piano_beginners_songbook.pdf
    • https://cdn.shopify.com/s/files/1/0429/1087/5815/files/aquatic_plants_list_with_pictures.pdf
    • https://cdn.shopify.com/s/files/1/0431/3245/3030/files/spcc_plan_reporting_requirements.pdf
    • https://cdn.shopify.com/s/files/1/0431/6482/7805/files/vizomeleguvewedumoniwefo.pdf
    • https://static.usrfiles.com/ugd/5bb01c_6669adef24724f888d70f64164eb21f4.pdf
    • https://static.usrfiles.com/ugd/b8c837_4493b3712e744fbdae29f68889328556.pdf
    • https://static.usrfiles.com/ugd/ab922d_bf576d0cde5345c181e50dc22ac6a669.pdf
    • https://static.usrfiles.com/ugd/b444d4_3c4cd7b096be4f8792f453a99b8116a0.pdf
    • https://cdn.shopify.com/s/files/1/0433/7994/9733/files/sapulibel.pdf
    • https://cdn.shopify.com/s/files/1/0430/4899/2919/files/61928003543.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_005_off00009417.bin
22b16f7f9ce2d8a54a4f562d958a663674ea14de1c5183f42fbcc25b6a88b25b
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x9417 18448 bytes
font_00_sfnt_off00005f59.bin
6801171530936ba52c0e5acc8a98bb4584dc26389eee805f41e2e359c8a54775
pdf-font-stream PDF embedded font (sfnt) at offset 0x5F59 5240 bytes
font_01_sfnt_off0000711b.bin
3c0b1420a48eb84b01ae13b0124ab0a63d915601ebcfeb473c11934320ed18f4
pdf-font-stream PDF embedded font (sfnt) at offset 0x711B 10208 bytes