Malicious PDF — malware analysis report

Static analysis result for SHA-256 8ff07fa0d467ab39…

MALICIOUS

PDF

46.6 KB Created: 2020-08-15 06:19:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4930df6f5b19a870dc02917102e24ea9 SHA-1: fdf1b469d38f84a164c0df716a656c19b921fb04 SHA-256: 8ff07fa0d467ab390d92c45eb26eb736e85df57f5075def83b11364a610c1464
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a high number of embedded links, many pointing to Shopify domains, but one critical link directs to `ttraff.ru`, identified as a malicious redirector. The document body and heuristics indicate a lure for MFA or one-time code harvesting, consistent with credential phishing. The primary malicious URL is `https://ttraff.ru/pify?keyword=icloud+photos+to+android+transfer`, which likely serves as the initial entry point for further malicious activity.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • MFA / one-time-code harvesting lure high SE_MFA_LURE
    Document asks for a one-time code, authenticator approval, or MFA confirmation — consistent with credential phishing kits that steal session tokens or abuse multi-factor authentication
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=icloud+photos+to+android+transfer
    • http://files.inthepinesboutique.com/uploads/1/3/2/6/132681861/losesulowepi_pesozamiwuxeles.pdf
    • https://cdn.shopify.com/s/files/1/0438/3653/9045/files/emulator_8086_tutorial.pdf
    • https://cdn.shopify.com/s/files/1/0433/9240/1558/files/8015712341.pdf
    • https://cdn.shopify.com/s/files/1/0433/0677/8784/files/74524891183.pdf
    • https://cdn.shopify.com/s/files/1/0433/6828/4319/files/volinorimid.pdf
    • https://cdn.shopify.com/s/files/1/0429/3391/1705/files/99164593216.pdf
    • https://cdn.shopify.com/s/files/1/0429/3269/9302/files/85297630894.pdf
    • https://cdn.shopify.com/s/files/1/0432/6454/0840/files/34156849650.pdf
    • https://cdn.shopify.com/s/files/1/0432/6876/7912/files/lobatojawesefifagupenabu.pdf
    • https://cdn.shopify.com/s/files/1/0440/1908/9566/files/zefanunun.pdf
    • https://cdn.shopify.com/s/files/1/0430/3526/3138/files/chernobyl_accidente.pdf
    • https://cdn.shopify.com/s/files/1/0429/9702/2871/files/86937272137.pdf
    • https://cdn.shopify.com/s/files/1/0435/6957/8147/files/classic_warrior_macros.pdf
    • https://cdn.shopify.com/s/files/1/0432/1778/0896/files/vuxigopeparaseleti.pdf
    • https://cdn.shopify.com/s/files/1/0441/3577/6408/files/activate_a2.pdf
    • https://cdn.shopify.com/s/files/1/0438/1320/8224/files/agenda_mercantil_2020_gratis.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006cad.bin
269634c0cf96925464f587bc3454d3a38e0c133b03f0296588c21cde89b75acb
pdf-font-stream PDF embedded font (sfnt) at offset 0x6CAD 5064 bytes
font_01_sfnt_off00007dca.bin
5e72c4e15ca083d7a526a82c04729842bd382e96d8ec8631cc56c4243dcd6fea
pdf-font-stream PDF embedded font (sfnt) at offset 0x7DCA 9788 bytes
font_02_sfnt_off00009f2b.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0x9F2B 4324 bytes