Malicious PDF — malware analysis report

Static analysis result for SHA-256 8b41ca32c158af21…

MALICIOUS

PDF

61.2 KB Created: 2020-08-21 12:05:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fed64ad9483b5c7703b1d23c6331ca33 SHA-1: 3a8352767893e4d711534d1b3f9759f2ad01d820 SHA-256: 8b41ca32c158af219a92cb133d67770c8e92774e2f5e6e90cd2f4f4c8c6a53ad
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://ttraff.ru/pify?keyword=zagat+guide+tokyo'. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded links to Shopify-hosted PDFs, suggesting an attempt to manipulate search engine results or distribute content. The document body, though heavily corrupted, contains the target URL and mentions 'Zagat guide tokyo', reinforcing the lure. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=zagat+guide+tokyo
    • http://files.creativedesignconcepts.biz/uploads/1/3/0/9/130969053/vomopemus.pdf
    • http://files.danielledesnoyersphotography.com/uploads/1/3/0/7/130776111/fesokekolakasejow.pdf
    • http://wugaraz.diazpa.com/uploads/1/3/0/7/130738837/111063.pdf
    • http://files.thecollegescout.com/uploads/1/3/1/6/131636956/393697.pdf
    • http://files.paultophamphotography.org/uploads/1/3/1/3/131380493/6910943.pdf
    • https://cdn.shopify.com/s/files/1/0429/3849/9235/files/9375818080.pdf
    • https://cdn.shopify.com/s/files/1/0430/8808/5145/files/87944406906.pdf
    • https://cdn.shopify.com/s/files/1/0431/3631/9639/files/21485651298.pdf
    • https://cdn.shopify.com/s/files/1/0429/9656/4131/files/lozofedugorabolu.pdf
    • https://cdn.shopify.com/s/files/1/0430/6649/1031/files/bodie_kane_marcus_investments.pdf
    • https://cdn.shopify.com/s/files/1/0430/3519/7602/files/zolelusepoluwaseduje.pdf
    • https://cdn.shopify.com/s/files/1/0434/6665/3858/files/urdu_encyclopedia_download.pdf
    • https://cdn.shopify.com/s/files/1/0427/5997/9174/files/zogevatotugopisisi.pdf
    • https://cdn.shopify.com/s/files/1/0430/2657/9610/files/dental_management_of_cerebral_palsy.pdf
    • https://cdn.shopify.com/s/files/1/0437/3938/1912/files/nejik.pdf
    • https://cdn.shopify.com/s/files/1/0434/6196/8025/files/tecnologa_blockchain.pdf
    • https://cdn.shopify.com/s/files/1/0438/3778/4229/files/pevedizadiwuvugavi.pdf
    • https://cdn.shopify.com/s/files/1/0431/8491/4583/files/srimad_bhagavatam_ttd.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a7de.bin
4f429dc53ffe56680e61cd423f484208e3a1b7a198ea61d91dbbc17cc00d106b
pdf-font-stream PDF embedded font (sfnt) at offset 0xA7DE 4584 bytes
font_01_sfnt_off0000b790.bin
0288b130557b44c4d8e51f6000f7de1bc1293955e2dd40a35d9429c66cf410ce
pdf-font-stream PDF embedded font (sfnt) at offset 0xB790 10076 bytes
font_02_sfnt_off0000d9f2.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0xD9F2 4324 bytes