Malicious PDF — malware analysis report

Static analysis result for SHA-256 9b707ced82fb46a8…

MALICIOUS

PDF

51.8 KB Created: 2020-09-08 12:18:00 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e9c123587318ffda2113fa18be202ae3 SHA-1: 744b7e1a659e3abfbdceb8624477ef3f6c3efc0b SHA-256: 9b707ced82fb46a8bbcbf8e8d167dbfb6cf448db33b611fac48cdf7662617043
130 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains numerous embedded links, a significant portion of which point to a link farm hosted on Shopify. One of these links, https://ttraff.club/wix?keyword=rybka+chess+engine+for+android, is identified as a malicious redirector. The presence of a 'download button' heuristic further suggests a social engineering lure to trick users into clicking the malicious link. No scripts were extracted, and the document body is heavily obfuscated, but the primary attack vector appears to be redirection to malicious infrastructure.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=rybka+chess+engine+for+android
    • https://cdn.shopify.com/s/files/1/0431/6043/6896/files/85022084704.pdf
    • https://cdn.shopify.com/s/files/1/0436/9950/3254/files/discussion_method_of_teaching_advantages_and_disadvantages.pdf
    • https://cdn.shopify.com/s/files/1/0430/9689/9745/files/lafasititawogureko.pdf
    • https://cdn.shopify.com/s/files/1/0428/8629/9815/files/59547646273.pdf
    • https://static.usrfiles.com/ugd/77941b_e6e11fbf445d4454969ec909b1ea4f31.pdf
    • https://static.usrfiles.com/ugd/e4d7df_a131c3a07b1a4ff6b8ed8d91296becf4.pdf
    • https://static.usrfiles.com/ugd/469aea_ed89cb7d53ab4f1b956f33411de4369e.pdf
    • https://cdn.shopify.com/s/files/1/0428/2544/9628/files/xetebosopijibiropero.pdf
    • https://cdn.shopify.com/s/files/1/0438/0449/1938/files/10509752014.pdf
    • https://static.usrfiles.com/ugd/c618e9_c17022ffbf64489ebe556ea77806b8c6.pdf
    • https://static.usrfiles.com/ugd/275374_a380639f14da44d0b6ca3ee437fc57f3.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007caa.bin
be33a5e284080c8355e70829209e0e2cfe9dc421c9393738740f12b113b966e3
pdf-font-stream PDF embedded font (sfnt) at offset 0x7CAA 5272 bytes
font_01_sfnt_off00008e85.bin
4354b62fbdd01d9629ee3f5fc52f5ed745ae856b18ba265f94b0674694a0f8ce
pdf-font-stream PDF embedded font (sfnt) at offset 0x8E85 11152 bytes
font_02_sfnt_off0000b495.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0xB495 4324 bytes