Malicious PDF — malware analysis report

Static analysis result for SHA-256 9d19943efb428099…

MALICIOUS

PDF

52.1 KB Created: 2020-08-15 06:44:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e0a6b7922f17f8298bbc4559c57d43ae SHA-1: 73e736cb2b259808e88ba49434f8fe3065c0e148 SHA-256: 9d19943efb42809972f6c96798de7c45399f7e7114f811718378714df49d9d51
130 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a link farm designed to redirect users to malicious content, disguised as a download for "2019 bollywood hit songs zip file". The primary malicious URL identified is https://ttraff.ru/pify?keyword=2019+bollywood+hit+songs+zip+file. The document also contains numerous other links to PDF files hosted on Shopify, likely to improve search engine ranking and mask malicious activity. No scripts were extracted, and the document body is heavily obfuscated.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=2019+bollywood+hit+songs+zip+file
    • http://files.mocins.com/uploads/1/3/0/9/130969153/7049282.pdf
    • http://files.windmillpreschoolbrill.com/uploads/1/3/1/6/131637357/sofumemifoxese.pdf
    • https://cdn.shopify.com/s/files/1/0432/9252/4702/files/pusudusanumisad.pdf
    • https://cdn.shopify.com/s/files/1/0437/8460/1758/files/nodakabodidi.pdf
    • https://cdn.shopify.com/s/files/1/0428/1267/0111/files/toganutiwoxojakisomo.pdf
    • https://cdn.shopify.com/s/files/1/0432/1977/9741/files/prentice_hall_reference_guide.pdf
    • https://cdn.shopify.com/s/files/1/0434/8579/0365/files/boxiredigogusu.pdf
    • https://cdn.shopify.com/s/files/1/0429/8260/4963/files/cecillia_wang.pdf
    • https://cdn.shopify.com/s/files/1/0429/2499/8819/files/espresso_english_grammar_level_4.pdf
    • https://cdn.shopify.com/s/files/1/0437/5327/5546/files/kofazudel.pdf
    • https://cdn.shopify.com/s/files/1/0428/2934/9030/files/jimen.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000648f.bin
d618e367fa50796a48c9f49498acd02235ff8eae6624d24989ef2c891e050820
pdf-font-stream PDF embedded font (sfnt) at offset 0x648F 5768 bytes
font_01_sfnt_off00007840.bin
f83932257a38571f82aa189523e34f7bad5130950d7ca20d673e3f7311adfbe4
pdf-font-stream PDF embedded font (sfnt) at offset 0x7840 6644 bytes
font_02_sfnt_off000089e3.bin
46851a5e3f8099281149f5e75ee7883bf1d08bba55ff881a0d2ca2a2399134c8
pdf-font-stream PDF embedded font (sfnt) at offset 0x89E3 12968 bytes
font_03_sfnt_off0000b2f5.bin
266b939c9338ead1891b096f012eea199e478691fbfff715d753d73670228676
pdf-font-stream PDF embedded font (sfnt) at offset 0xB2F5 4500 bytes