Malicious PDF — malware analysis report

Static analysis result for SHA-256 4e18e853f771ee94…

MALICIOUS

PDF

35.1 KB Created: 2020-08-20 04:22:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 759c19448e81fcaa5c438191848effd3 SHA-1: 94539d27aa09e0c308a7d5d992663df3db1ef6b0 SHA-256: 4e18e853f771ee94ec55f1b19a0fd018aca4883dc1e357f8e2d579197b9b1517
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a significant number of embedded links, identified as a link farm. The primary URL, https://ttraff.ru/pify?keyword=avtar+brah+cartographies+of+diaspora+pdf, is flagged as a malicious redirector. This suggests the document's purpose is to direct users to malicious sites, potentially for phishing or malware distribution, leveraging SEO techniques to mask its true intent. No scripts were extracted, limiting the analysis of direct payload execution.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=avtar+brah+cartographies+of+diaspora+pdf In PDF document text
    • http://files.mamatgear.com/uploads/1/3/2/7/132712676/xonipebiw.pdfIn PDF document text
    • http://files.leadinggreendistributing.com/uploads/1/3/0/7/130740264/f897ce9656ee4b4.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0434/1868/1496/files/34675638658.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0435/1367/5928/files/41349234952.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0432/7738/5892/files/jelexupemuriwugibujufukad.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0435/1921/3727/files/balance_sheet_template_for_small_business_uk.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0438/9657/0024/files/business_ethics_subject.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0438/6720/9893/files/history_of_english_literature_by_mundra_download.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0430/3493/5447/files/mujolenusedon.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0432/8423/4398/files/book_of_elijah.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0430/0118/4417/files/21951228821.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0431/5689/7947/files/77109629848.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0432/9635/8565/files/89358628794.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0435/9208/9759/files/wuwebotoji.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004c53.bin
0f53caeaf7fc0a5f4d6b70fbb934c0581e3c0768b6b8a8d0fb30198cba6e30fa
pdf-font-stream PDF embedded font (sfnt) at offset 0x4C53 5572 bytes
font_01_sfnt_off00005f3c.bin
0b7998de4c7aaf022c0008093f8f4f07b2d3e27d5f16f405c9ec3f95df83f7b6
pdf-font-stream PDF embedded font (sfnt) at offset 0x5F3C 9492 bytes