Malicious PDF — malware analysis report

Static analysis result for SHA-256 4c5072f4860d780e…

MALICIOUS

PDF

60.5 KB Created: 2020-08-04 07:12:46 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 69361b9b3416ecb9ef7fe8ccf8e97c5a SHA-1: 2985ebccd938fd852bc84de56a31aff19c3ef7c0 SHA-256: 4c5072f4860d780e24ec2163875a7f4eec099c3ed0abda6579c4a7d02630390f
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains numerous links, many of which point to a link farm hosted on cdn.shopify.com, likely for SEO poisoning. One critical heuristic identified a link to a known malicious redirector infrastructure at ttraff.ru. The document body, though heavily obfuscated, contains the same URL, suggesting the primary intent is to redirect users to malicious content. The file was authored using wkhtmltopdf, a tool often used to generate PDFs from web content, which aligns with the link farm and redirection tactics.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=death+of+a+salesman+novel+pdf
    • http://files.thehonestcatholic.com/uploads/1/3/1/4/131438151/xuboxobegenitufi.pdf
    • http://files.minercountyhistoricalsociety.org/uploads/1/3/1/3/131380467/f313d2.pdf
    • http://files.galenacreekvisitorcenter.org/uploads/1/3/0/7/130776254/vatiwobefik.pdf
    • http://files.candlewyckhomes.com/uploads/1/3/2/7/132712435/9262116.pdf
    • https://cdn.shopify.com/s/files/1/0428/7974/6201/files/vinurubufifobi.pdf
    • https://cdn.shopify.com/s/files/1/0432/0398/5570/files/32461500442.pdf
    • https://cdn.shopify.com/s/files/1/0432/7096/3350/files/genen.pdf
    • https://cdn.shopify.com/s/files/1/0435/9795/5229/files/tijijajuvevi.pdf
    • https://cdn.shopify.com/s/files/1/0432/3917/8399/files/17469367534.pdf
    • https://cdn.shopify.com/s/files/1/0435/5896/1315/files/ruvav.pdf
    • https://cdn.shopify.com/s/files/1/0436/6431/0425/files/verasadejuzitusov.pdf
    • https://cdn.shopify.com/s/files/1/0434/3313/2184/files/69975246198.pdf
    • https://cdn.shopify.com/s/files/1/0431/4487/2085/files/stihl_fs_45_parts_list_manual.pdf
    • https://cdn.shopify.com/s/files/1/0433/4164/3928/files/wanamigogagudetafisi.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/73881495537.pdf
    • https://cdn.shopify.com/s/files/1/0441/3263/0680/files/fujamikopetivewuxujejoti.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000aff0.bin
5bf9bfad263b343620b895a99f4b7d69b87223df04041d55511af4fd15e753eb
pdf-font-stream PDF embedded font (sfnt) at offset 0xAFF0 5244 bytes
font_01_sfnt_off0000c1b7.bin
fb458541b813bc5b8428f8d7b2834cea8a1497d02083c5b8e0c96807969c4221
pdf-font-stream PDF embedded font (sfnt) at offset 0xC1B7 10384 bytes