Malicious PDF — malware analysis report

Static analysis result for SHA-256 89aa8a9199245948…

MALICIOUS

PDF

50.2 KB Created: 2020-08-07 20:45:46 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4de2f16a51035cf6234946233534d743 SHA-1: 4feae5f451253f9dd4039230508fd82e99d539dc SHA-256: 89aa8a91992459482669f211ef8f5c4163bccec630048db11c833a74702b6716
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link farm designed to appear as a legitimate 'algorithm complexity cheat sheet' but redirects to a malicious domain. The primary malicious URL is https://ttraff.ru/pify?keyword=algorithm+complexity+cheat+sheet+pdf, which is flagged as a redirector. The document body, though heavily obfuscated, contains this URL and numerous other benign-looking Shopify links, likely to improve search engine ranking and mask malicious activity. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=algorithm+complexity+cheat+sheet+pdf
    • http://files.accsyracuse.org/uploads/1/3/1/3/131384709/1ceff8c4520ff.pdf
    • http://files.danielphotographyltd.com/uploads/1/3/1/4/131453674/ce1fd.pdf
    • http://files.greenpowersystem.net/uploads/1/3/2/8/132815183/ab302cc9bf17d9.pdf
    • http://wilanuni.arminalamanna.com/uploads/1/3/1/4/131453109/rojuzod-wuxis-fotof-zorarikusa.pdf
    • http://ketesek.poweroftheflowers.com/uploads/1/3/1/3/131384401/5585e240ca79.pdf
    • https://cdn.shopify.com/s/files/1/0431/5817/5895/files/70416408434.pdf
    • https://cdn.shopify.com/s/files/1/0431/3733/5464/files/12501997878.pdf
    • https://cdn.shopify.com/s/files/1/0435/2176/9627/files/air_washer_system_design.pdf
    • https://cdn.shopify.com/s/files/1/0440/6041/0021/files/34020354412.pdf
    • https://cdn.shopify.com/s/files/1/0431/0574/7095/files/3009750044.pdf
    • https://cdn.shopify.com/s/files/1/0437/2529/1671/files/30291990832.pdf
    • https://cdn.shopify.com/s/files/1/0432/0047/9391/files/faxefosijakadoros.pdf
    • https://cdn.shopify.com/s/files/1/0430/0272/4506/files/borex.pdf
    • https://cdn.shopify.com/s/files/1/0451/2422/3141/files/cadenas_de_markov_ejercicios_resueltos.pdf
    • https://cdn.shopify.com/s/files/1/0429/2762/0249/files/31123039476.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005f45.bin
8ca1deac3ef3003cf76904e3e4bb6a8c93d87e1d82e7d7e624793d2aeff4ee42
pdf-font-stream PDF embedded font (sfnt) at offset 0x5F45 5728 bytes
font_01_sfnt_off000072af.bin
8080e25310b2e8f2e6e15dcdbea9c7dbccbd2d100bc7eaea8a13e6766e6cf6f1
pdf-font-stream PDF embedded font (sfnt) at offset 0x72AF 16344 bytes
font_02_sfnt_off0000a557.bin
84a0ab111ae67c7570bc6eb778488b810f8f4c7f73d79f9b0e58fd164bce43bc
pdf-font-stream PDF embedded font (sfnt) at offset 0xA557 16500 bytes