Malicious PDF — malware analysis report

Static analysis result for SHA-256 9b5d0de508775210…

MALICIOUS

PDF

45.9 KB Created: 2020-08-14 06:56:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8936c9063129bb8550ebd79f656e7f69 SHA-1: 06fdd4bfe18c06556a49a1327aa4ad660aaf3948 SHA-256: 9b5d0de508775210501549ec6055d7dd83d00722458044e0936feb4e2c8b5ae5
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing for a malicious redirector link pointing to 'https://ttraff.ru/pify?keyword=avast+android+antivirus+apk'. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded links to external PDFs hosted on platforms like Shopify and other domains. The document body, though heavily obfuscated, also contains the same suspicious URL, suggesting a deliberate attempt to lure users into clicking it, likely for phishing or malware distribution.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=avast+android+antivirus+apk
    • http://files.sydneybroadaway.com/uploads/1/3/1/3/131398052/7cc3e4.pdf
    • http://files.oldsheriffshouse.org/uploads/1/3/1/4/131453555/9045072.pdf
    • http://desag.daniellevannucci.com/uploads/1/3/2/6/132695569/fb95091dd0b55.pdf
    • http://gebavisu.kinseekergenealogy.com/uploads/1/3/2/8/132814930/vevupajilow.pdf
    • http://files.decemberschildrennd.com/uploads/1/3/2/7/132741352/9260449.pdf
    • https://cdn.shopify.com/s/files/1/0436/2207/2480/files/rewutevofofapi.pdf
    • https://cdn.shopify.com/s/files/1/0438/4777/8469/files/60467205652.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/63032467643.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/52325197595.pdf
    • https://cdn.shopify.com/s/files/1/0433/4603/4846/files/i_see_the_light_lyrics.pdf
    • https://cdn.shopify.com/s/files/1/0438/0426/2561/files/porozozarawin.pdf
    • https://cdn.shopify.com/s/files/1/0429/9633/4753/files/49121580113.pdf
    • https://cdn.shopify.com/s/files/1/0439/1141/3915/files/lozutibufekadenamelofuwi.pdf
    • https://cdn.shopify.com/s/files/1/0431/2812/7650/files/reading_comprehension_test_intermediate_level.pdf
    • https://cdn.shopify.com/s/files/1/0431/9775/9643/files/9845978797.pdf
    • https://cdn.shopify.com/s/files/1/0433/0727/0312/files/free_throw_championship_entry_form_score_sheet.pdf
    • https://cdn.shopify.com/s/files/1/0430/9401/6157/files/wejoz.pdf
    • https://cdn.shopify.com/s/files/1/0430/8343/2096/files/58685762528.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006165.bin
0b1559d16ee65249decb0d099389c554bd2d933ae355d7e5d0f42496fb486a57
pdf-font-stream PDF embedded font (sfnt) at offset 0x6165 5032 bytes
font_01_sfnt_off00007293.bin
297b326e13c208013c7334b5fc9a90d4b7e51ee756cbaac815fa5effd75c2f9a
pdf-font-stream PDF embedded font (sfnt) at offset 0x7293 10060 bytes
font_02_sfnt_off0000954f.bin
f0a8b786da721c7415a59d91fbce3b20bbb98ea32e48857ac1ff22d53b00ec29
pdf-font-stream PDF embedded font (sfnt) at offset 0x954F 16144 bytes