Malicious PDF — malware analysis report

Static analysis result for SHA-256 8ab33b2d60e18c6c…

MALICIOUS

PDF

45.5 KB Created: 2020-08-20 05:41:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 76bf033629d8ecb0c8c26346ccdbd094 SHA-1: bafd03e11e9c77424c4c4d8fca605440eec0667c SHA-256: 8ab33b2d60e18c6c184b07331f922659bee5a37d114cc012e47cfe7c8a4d1d77
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, many of which point to external PDFs hosted on Shopify. One of these links, 'https://ttraff.ru/pify?keyword=multiplicative+inverse+of+complex+numbers+worksheet', is identified as a malicious redirector. The document body, though heavily obfuscated, also contains this URL, suggesting the primary intent is to lure the user to this malicious site. The file's structure and the presence of numerous links indicate a link farm or redirection tactic.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=multiplicative+inverse+of+complex+numbers+worksheet
    • http://pobosu.staffordengines.com/uploads/1/3/0/7/130775432/d01b6d332dff04.pdf
    • http://wikamiv.deinehandwerker.ch/uploads/1/3/1/4/131406821/3822024.pdf
    • https://cdn.shopify.com/s/files/1/0432/0192/1184/files/vusamiriboxetixawo.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/fakuwonilojovaxibudebu.pdf
    • https://cdn.shopify.com/s/files/1/0429/7303/6697/files/motogp_2016_tv_schedule.pdf
    • https://cdn.shopify.com/s/files/1/0429/9938/2170/files/98302712968.pdf
    • https://cdn.shopify.com/s/files/1/0452/2328/0800/files/vocabulary_games_for_the_classroom_lindsay_carleton.pdf
    • https://cdn.shopify.com/s/files/1/0431/7341/3028/files/jurisevusu.pdf
    • https://cdn.shopify.com/s/files/1/0429/7054/6335/files/73272376863.pdf
    • https://cdn.shopify.com/s/files/1/0434/6180/4197/files/92725144946.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/rewosegukedisupagur.pdf
    • https://cdn.shopify.com/s/files/1/0433/1316/8542/files/suwelazopotivejataburif.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/gidawibozifuniji.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com/s/files/1/0452/2328/0800/f

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006775.bin
ea5f689165b76110c0ea7252f625370f6a78a7c21c28e8271f58288eb65c9b43
pdf-font-stream PDF embedded font (sfnt) at offset 0x6775 5684 bytes
font_01_sfnt_off00007ab4.bin
936c48464d7c6688789bf6a95592efddee466dc729622db7d512a0ae88d706e8
pdf-font-stream PDF embedded font (sfnt) at offset 0x7AB4 14836 bytes