Malicious PDF — malware analysis report

Static analysis result for SHA-256 79ab85abaa383f8d…

MALICIOUS

PDF

79.2 KB Created: 2020-08-30 17:52:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6568ce57e535a13d7b6e9b7cfb89b93d SHA-1: 0a2005d53a6a4945778efa714fa2d213051ac9de SHA-256: 79ab85abaa383f8df2f5b9356d3d1a42e4a11122ebd70c2a094e60076be36652
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.001 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link, pointing to 'ttraff.ru'. This URL is presented within the document body, disguised as a search result for 'Ponyo on the cliff by the sea english dub'. The PDF also contains a heuristic for a link farm, with 19 external PDF links, many hosted on 'static.usrfiles.com'. The primary malicious IOC is the redirector URL, which likely leads to further malicious content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=ponyo+on+the+cliff+by+the+sea+english+dub
    • https://static.usrfiles.com/ugd/b77b08_a72550397fdd4fe2b7bafc62bba90493.pdf
    • https://static.usrfiles.com/ugd/b8c837_f7ab4f29fb2a47d6b67267b97015b512.pdf
    • https://static.usrfiles.com/ugd/f523c3_138d9cb4a5f24ca8b49d71fb3474926b.pdf
    • https://static.usrfiles.com/ugd/b7ab08_a8a244fa1bd74dc683912edb3dfcc4fe.pdf
    • https://static.usrfiles.com/ugd/b8c837_e861cdc6299c4cf8adb30d40da9b057c.pdf
    • https://static.usrfiles.com/ugd/8b2c09_de0b83adff02441ab9f13adb7979fa64.pdf
    • https://static.usrfiles.com/ugd/04e6f9_6c8d9606692240458bdf4bcbb5ca95b4.pdf
    • https://static.usrfiles.com/ugd/d2cc1f_0f546505430a4212a3f9491c22370593.pdf
    • https://static.usrfiles.com/ugd/dd4472_6e051a161a774fddaf427fc25020c37a.pdf
    • https://cdn.shopify.com/s/files/1/0432/2865/9874/files/alter_ego_a1_archive.pdf
    • https://cdn.shopify.com/s/files/1/0434/2166/3397/files/balance_ton_quoi_partition_piano.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/nagexonulelaxefirulilona.pdf
    • https://cdn.shopify.com/s/files/1/0432/1578/2048/files/rosol.pdf
    • https://cdn.shopify.com/s/files/1/0430/7386/3842/files/similarity_report_essay.pdf
    • https://static.usrfiles.com/ugd/b8c837_0675bf0d342c4dc788b86726e2943cd5.pdf
    • https://static.usrfiles.com/ugd/fb83f1_3acc6d6eb80f4a4fb63bf440310a2d3b.pdf
    • https://static.usrfiles.com/ugd/d775a9_48cb428f460d44b3875d0efb2d2ae795.pdf
    • https://static.usrfiles.com/ugd/b8c837_356230d3c3694ca8af539d8cba9a1ce1.pdf
    • https://static.usrfiles.com/ugd/b0b521_0a366a2599cd4115b62a6ba80886226a.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a471.bin
da0ca4baf0047c1df5881b4ab189fd41462be209d6dd0b019313072b9a2ffe8d
pdf-font-stream PDF embedded font (sfnt) at offset 0xA471 26224 bytes
font_01_sfnt_off0000f71f.bin
047eca59303707bf7b903b132b82a7db92256805134865340bd4140e425a263b
pdf-font-stream PDF embedded font (sfnt) at offset 0xF71F 5432 bytes
font_02_sfnt_off00010992.bin
dbc95a7ec315ccc018b9eed963accd1246c607a9607e7556c0025e3886e16760
pdf-font-stream PDF embedded font (sfnt) at offset 0x10992 10888 bytes