Malicious PDF — malware analysis report

Static analysis result for SHA-256 8cadeb53f3ab86d4…

MALICIOUS

PDF

48.5 KB Created: 2020-08-11 19:22:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 93f604e7137a98cb6b02e439b7a00383 SHA-1: faa1dcd81fc9bf7379972c9dbaa895d4a67a4d2a SHA-256: 8cadeb53f3ab86d47a62c52620ef5c8be4c67f9c1903842385cea3df16881cbb
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains numerous embedded links, a common tactic for SEO spam and phishing. One critical heuristic firing indicates a malicious redirector link pointing to 'ttraff.ru'. The document body also contains this URL, suggesting the primary intent is to redirect users to malicious content or scams. The file was authored using wkhtmltopdf, which can be used to generate PDFs from web content, potentially for malicious purposes.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=french+to+english+pdf+translation+online
    • http://files.newageoflight.com/uploads/1/3/2/6/132681463/belegodevo.pdf
    • http://zodez.lightingcreativefires.com/uploads/1/3/1/0/131071164/9954650.pdf
    • http://wukasizo.rockymountainraconteur.ca/uploads/1/3/0/7/130775350/pikonupazop-zanupelo.pdf
    • http://nuxivorov.sevenseasonsfarm.com/uploads/1/3/0/9/130969352/gatakibegodelerugag.pdf
    • http://files.calgarymathtutor.com/uploads/1/3/2/7/132710780/4896061.pdf
    • http://wukasizo.rockymountainraconteur.ca/uploads
    • https://cdn.shopify.com/s/files/1/0437/7726/1729/files/apollo_tyres_annual_report_2020.pdf
    • https://cdn.shopify.com/s/files/1/0427/7751/0055/files/web_page_to_without_ads.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/tedogunugovosilogupex.pdf
    • https://cdn.shopify.com/s/files/1/0428/1758/5308/files/27626444873.pdf
    • https://cdn.shopify.com/s/files/1/0427/8062/3015/files/neluvatafisobofofim.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/8685957786.pdf
    • https://cdn.shopify.com/s/files/1/0431/2052/5469/files/89723628292.pdf
    • https://cdn.shopify.com/s/files/1/0430/9775/1709/files/printable_activities_for_adults.pdf
    • https://cdn.shopify.com/s/files/1/0434/4764/8406/files/17211249401.pdf
    • https://cdn.shopify.com/s/files/1/0433/6985/7176/files/america_continent_map.pdf
    • https://cdn.shopify.com/s/files/1/0434/5459/5224/files/nenifikifajesa.pdf
    • https://cdn.shopify.com/s/files/1/0432/8249/7701/files/91741137723.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007f88.bin
97e485b1000238707aa3f3f64b3f5e176b732a3d332f21a89608e925a355d5fe
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F88 5372 bytes
font_01_sfnt_off000091c5.bin
26eb7b14bc0b5a915e7fe9f9da5c5c7d472c6441fc55005577b57ac9908d3b35
pdf-font-stream PDF embedded font (sfnt) at offset 0x91C5 10192 bytes