Malicious PDF — malware analysis report

Static analysis result for SHA-256 428a29bf11572499…

MALICIOUS

PDF

51.6 KB Created: 2020-08-10 21:43:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5b4f33a058b886d99334212818cb3008 SHA-1: 070c40717f1b1cd6e130f3b9e01a2d0018310379 SHA-256: 428a29bf115724993ef1750d5281c696c7fd81d5c36a156e413c926154a8b806
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a heuristic firing for a malicious redirector link, specifically pointing to 'ttraff.ru'. The document body, though heavily obfuscated, contains text related to 'Warner Bros Abu Dhabi map pdf' and includes numerous embedded URLs, many hosted on Shopify, but also several on less reputable domains. The primary malicious link is 'https://ttraff.ru/pify?keyword=warner+bros+abu+dhabi+map+pdf', which likely serves as a lure to a malicious site. The PDF also exhibits characteristics of a link farm, with many external PDF links, suggesting a broader SEO poisoning or content spamming campaign. No scripts were extracted, limiting the analysis of direct payload execution.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=warner+bros+abu+dhabi+map+pdf
    • http://files.unleashyourpower.org/uploads/1/3/1/4/131436956/5206702.pdf
    • http://files.drawntolead.org/uploads/1/3/1/6/131606984/nodogaguma.pdf
    • http://files.espressowilltravel.com/uploads/1/3/1/4/131453156/lekaxawijesek-gulorogokavu-zarakakiro-vibok.pdf
    • https://cdn.shopify.com/s/files/1/0440/7335/3366/files/gapekekizojesilanive.pdf
    • https://cdn.shopify.com/s/files/1/0431/6046/9660/files/activity_based_cost_management.pdf
    • https://cdn.shopify.com/s/files/1/0437/3151/7605/files/33767986135.pdf
    • https://cdn.shopify.com/s/files/1/0430/6790/0061/files/82777965689.pdf
    • https://cdn.shopify.com/s/files/1/0427/8976/5276/files/lafemumefis.pdf
    • https://cdn.shopify.com/s/files/1/0433/5557/0341/files/77509573454.pdf
    • https://cdn.shopify.com/s/files/1/0435/9120/5021/files/stereogram_book.pdf
    • https://cdn.shopify.com/s/files/1/0431/9451/5614/files/electric_circuits_9th_edition_solutions_manual.pdf
    • https://cdn.shopify.com/s/files/1/0438/7235/4459/files/catalina_island_fishing.pdf
    • https://cdn.shopify.com/s/files/1/0435/0722/0635/files/raborabezobolil.pdf
    • https://cdn.shopify.com/s/files/1/0440/2734/7109/files/sekolozobufesete.pdf
    • https://cdn.shopify.com/s/files/1/0434/5020/4316/files/tapased.pdf
    • https://cdn.shopify.com/s/files/1/0445/4242/7295/files/pesibozumelogaxi.pdf
    • https://cdn.shopify.com/s/files/1/0440/5254/5701/files/juki_lu-_562.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008a94.bin
99d62cc1e91a5eb53662ead6a4b3d904c6d65fce552f872251effef965572379
pdf-font-stream PDF embedded font (sfnt) at offset 0x8A94 5400 bytes
font_01_sfnt_off00009cc5.bin
39c1785cfa9486be6a8589280de990f7c8d59059e1c1c5a2e3d2ef8641d486d0
pdf-font-stream PDF embedded font (sfnt) at offset 0x9CC5 10820 bytes