Malicious PDF — malware analysis report

Static analysis result for SHA-256 7cd2050ecc24b4ea…

MALICIOUS

PDF

46.7 KB Created: 2020-08-21 13:19:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5c18181aeb31887bc006bd543c81d046 SHA-1: 18bd0337af0a3718cd0672d2087049901e9f9d65 SHA-256: 7cd2050ecc24b4eadea1b78ed763fea65925d861575d7d99626ad0da79b2d965
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, many of which point to external PDF files hosted on Shopify. One of the primary links, however, leads to a known malicious redirector at 'ttraff.ru'. The document body text, though partially corrupted, includes the URL 'https://ttraff.ru/pify?keyword=classifying+shapes+worksheet+3rd+grade', suggesting a lure to disguise malicious activity. The presence of numerous links and the malicious redirector indicate an attempt to lead the user to harmful content, likely for further exploitation or credential harvesting.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=classifying+shapes+worksheet+3rd+grade
    • http://files.leasidearena.com/uploads/1/3/1/4/131455832/sowapinosivomoje.pdf
    • http://sugudate.nyheart.net/uploads/1/3/0/8/130874254/baniwuna.pdf
    • http://bisola.mucusless-diet.com/uploads/1/3/2/7/132712572/kisebibibixibu.pdf
    • https://cdn.shopify.com/s/files/1/0427/6623/7852/files/handbook_of_utility_theory.pdf
    • https://cdn.shopify.com/s/files/1/0432/6617/9230/files/27991118217.pdf
    • https://cdn.shopify.com/s/files/1/0434/4823/8241/files/zisovatodekegodol.pdf
    • https://cdn.shopify.com/s/files/1/0432/3383/7224/files/avery_business_card_template.pdf
    • https://cdn.shopify.com/s/files/1/0429/9672/7962/files/english_language_curriculum_guide_2017.pdf
    • https://cdn.shopify.com/s/files/1/0434/6026/4086/files/81874343255.pdf
    • https://cdn.shopify.com/s/files/1/0433/3027/3448/files/gogonejopekasudufi.pdf
    • https://cdn.shopify.com/s/files/1/0428/1162/1543/files/37219018591.pdf
    • https://cdn.shopify.com/s/files/1/0429/5265/5004/files/ad_d_monster_manual_2.pdf
    • https://cdn.shopify.com/s/files/1/0428/9911/2099/files/41349440409.pdf
    • https://cdn.shopify.com/s/files/1/0428/7873/0403/files/business_plan_pizza_restaurant.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000062c5.bin
d750ea6ea8fb76047e2818baf724db5a9383083a02ce3ae78494d4a8d02a11ce
pdf-font-stream PDF embedded font (sfnt) at offset 0x62C5 5632 bytes
font_01_sfnt_off000075f7.bin
282184335818ab1f2eec3c1f688d12ca387d2d25f01bf072156cd84084e32821
pdf-font-stream PDF embedded font (sfnt) at offset 0x75F7 10024 bytes
font_02_sfnt_off00009888.bin
586fd2d47d7ef655ac8fcedaf3a17ac43b55ee34544d24df6525aba8b365c669
pdf-font-stream PDF embedded font (sfnt) at offset 0x9888 16116 bytes