Malicious PDF — malware analysis report

Static analysis result for SHA-256 963b02ab11b6bb26…

MALICIOUS

PDF

41.4 KB Created: 2020-08-18 16:58:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7181124a91b2dfa39a69abb28eba9cd0 SHA-1: 0d767622810fe1f54b0e1ad2648ff1bbd6dd6757 SHA-256: 963b02ab11b6bb26cbafd4ee5148e036fafaa460acfa9a11c6b951dfd39d269d
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing for PDF_MALICIOUS_REDIRECTOR_LINK, indicating it directs users to malicious infrastructure. The embedded URL https://ttraff.ru/pify?keyword=baby+couple+pic+free is the primary indicator of this malicious redirection. The file also exhibits characteristics of a PDF link farm, with numerous links pointing to external PDFs, likely for SEO manipulation or to obscure the malicious redirector.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=baby+couple+pic+free
    • http://lowotupup.lifestylejewellery.com/uploads/1/3/0/7/130776326/bukulino_fixaludaf_fikebota.pdf
    • https://cdn.shopify.com/s/files/1/0428/9242/7430/files/canine_parvovirus_pada_anjing.pdf
    • https://cdn.shopify.com/s/files/1/0433/1582/2747/files/zuziragumijikotugup.pdf
    • https://cdn.shopify.com/s/files/1/0439/8468/3166/files/wefedebapebeso.pdf
    • https://cdn.shopify.com/s/files/1/0429/1595/4847/files/xizidigubeketibesul.pdf
    • https://cdn.shopify.com/s/files/1/0434/6390/1334/files/rosumojeboba.pdf
    • https://cdn.shopify.com/s/files/1/0430/3713/0914/files/tupotomorilafebu.pdf
    • https://cdn.shopify.com/s/files/1/0433/5098/2805/files/bozavetepirafa.pdf
    • https://cdn.shopify.com/s/files/1/0433/0877/7637/files/34417892470.pdf
    • https://cdn.shopify.com/s/files/1/0431/4647/7725/files/pebowusuraga.pdf
    • https://cdn.shopify.com/s/files/1/0427/9320/5916/files/jugabidokivafolara.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000050ec.bin
979d8c55da3ae5b6e938b844fbcfb883ba0f02ee1a3c191e432d35e119bb55a9
pdf-font-stream PDF embedded font (sfnt) at offset 0x50EC 5124 bytes
font_01_sfnt_off00006265.bin
9f9e5fb2d02851d8f4fb127d7a855d5b5e3e981b9769cba582695c98f117070f
pdf-font-stream PDF embedded font (sfnt) at offset 0x6265 9732 bytes
font_02_sfnt_off000083ea.bin
8c08a5ca30f7191253832396cd0e16b2863be47a0d76434bcfaca3abab847f9b
pdf-font-stream PDF embedded font (sfnt) at offset 0x83EA 16128 bytes