Malicious PDF — malware analysis report

Static analysis result for SHA-256 8e54a0eb48de3e37…

MALICIOUS

PDF

68.6 KB Created: 2020-08-02 08:12:59 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 533753a06848ae23946d7877001c4a9f SHA-1: f235095828b879c47017f3984386f26c48a5e321 SHA-256: 8e54a0eb48de3e37b54924326b24ac132c1a8efd74129414bc1343cd1f4d3686
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, with a critical heuristic firing indicating a 'PDF_SEO_LINK_FARM'. One of these links, 'https://ttraff.ru/pify?keyword=division+algorithm+proof', is flagged as a malicious redirector. The document body, though heavily obfuscated, appears to contain text related to the 'division algorithm proof' and includes the malicious URL, suggesting an attempt to lure users through deceptive content and redirect them to potentially harmful infrastructure.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=division+algorithm+proof
    • http://files.chloesantarossa.com/uploads/1/3/0/7/130776381/monipupiwakupil-fanamiraf-nagumezili.pdf
    • http://files.janefitzgeraldmusicstudio.com/uploads/1/3/1/4/131453918/2963a98afed82f0.pdf
    • http://files.ljusvart.com/uploads/1/3/1/3/131381681/vetufiwikit_barasij.pdf
    • http://files.carolinehubner.com/uploads/1/3/0/8/130815009/kajamak_tanulevowotokis_pelejuvizota.pdf
    • https://cdn.shopify.com/s/files/1/0433/5904/3749/files/kedenilujevupufod.pdf
    • https://cdn.shopify.com/s/files/1/0436/3694/9152/files/voponetupi.pdf
    • https://cdn.shopify.com/s/files/1/0428/9898/1030/files/60597662643.pdf
    • https://cdn.shopify.com/s/files/1/0432/3577/0532/files/12218831277.pdf
    • https://cdn.shopify.com/s/files/1/0431/6420/5216/files/24426353605.pdf
    • https://cdn.shopify.com/s/files/1/0428/5241/7703/files/76659086514.pdf
    • https://cdn.shopify.com/s/files/1/0431/0853/2380/files/66086592850.pdf
    • https://cdn.shopify.com/s/files/1/0434/3565/5335/files/76162050486.pdf
    • https://cdn.shopify.com/s/files/1/0432/2767/6829/files/fosemekepabuzovirulera.pdf
    • https://cdn.shopify.com/s/files/1/0431/6259/9584/files/26670765535.pdf
    • https://cdn.shopify.com/s/files/1/0430/4610/9345/files/3710972151.pdf
    • https://cdn.shopify.com/s/files/1/0430/7379/8298/files/gupezubomopu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a995.bin
c0a3ef0844a2085e19df421ae90615b60ab014ab422184711658be104163e4f7
pdf-font-stream PDF embedded font (sfnt) at offset 0xA995 5376 bytes
font_01_sfnt_off0000bbc1.bin
5817331e4318b385dc64ed2b1fbf9587ebe62e16030d8c2c64713dc2e9211bba
pdf-font-stream PDF embedded font (sfnt) at offset 0xBBC1 16392 bytes
font_02_sfnt_off0000ef47.bin
d99aca7c96dd68c9c39c525353b21b72f4346d35b0af0f2be73ecdcd659226e3
pdf-font-stream PDF embedded font (sfnt) at offset 0xEF47 16308 bytes