Malicious PDF — malware analysis report

Static analysis result for SHA-256 9db97bdb3dc92afe…

MALICIOUS

PDF

39.0 KB Created: 2020-08-31 09:43:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7486886d7226aabe5f0b605b71ea6794 SHA-1: d14374cc221c7383fcbd6f2fb05d398b8e9485e6 SHA-256: 9db97bdb3dc92afe5a34f3e1c6928ad501ff55a6aaec0e92d1f8f759099443f1
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to ttraff.ru. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded URLs. The document body contains garbled text and a URL that appears to be the same as the malicious redirector, suggesting an attempt to obscure or disguise the malicious link. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=phim+nga+b%25C3%25AD+danh+b%25E1%25BA%25A7y+s%25C3%25B3i+t%25E1%25BA%25ADp+5
    • https://static.usrfiles.com/ugd/7c30af_b201a7a435f94345b89350446034900e.pdf
    • https://static.usrfiles.com/ugd/b8c837_570843dfa00848aa8f001642ff081495.pdf
    • https://static.usrfiles.com/ugd/9c0842_f0fb18ba705040c38af3509bbca81f95.pdf
    • https://static.usrfiles.com/ugd/5b9a87_2625eb0834ca45ad8f1985dd9fccd816.pdf
    • https://cdn.shopify.com/s/files/1/0434/1723/9704/files/prepare_a_multiple_step_income_statement.pdf
    • https://cdn.shopify.com/s/files/1/0440/7685/9544/files/79441982523.pdf
    • https://cdn.shopify.com/s/files/1/0430/7327/4018/files/25681550029.pdf
    • https://static.usrfiles.com/ugd/8b9728_0569872eaf7c4d75a37bc86c58bdcc8f.pdf
    • https://static.usrfiles.com/ugd/5af86b_1653ec0c85c44162aca9551d19c5d7bf.pdf
    • https://static.usrfiles.com/ugd/9c0842_3c3cbdbf023640b4b0a1ffcc67fe122f.pdf
    • https://static.usrfiles.com/ugd/b8c837_de4e80c054064e80a40c774c694587f4.pdf
    • https://cdn.shopify.com/s/files/1/0431/0115/9575/files/autocad_drawing_viewer_for_mac.pdf
    • https://cdn.shopify.com/s/files/1/0432/0903/1840/files/atlantic_ocean_hurricane_formation.pdf
    • https://cdn.shopify.com/s/files/1/0432/9707/9460/files/konasofovizob.pdf
    • https://cdn.shopify.com/s/files/1/0430/9798/1089/files/60974081167.pdf
    • https://cdn.shopify.com/s/files/1/0432/7541/9798/files/67493393212.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004b9c.bin
ece5fb93d92718e7d4f55229c7a8e8132feda2b0dd8f313428dd68eb2ce6ee08
pdf-font-stream PDF embedded font (sfnt) at offset 0x4B9C 6320 bytes
font_01_sfnt_off00005f99.bin
47ee739d1d93252be291f69774d5a13c0c10ce9cb7ee52730223930ce5aeaebe
pdf-font-stream PDF embedded font (sfnt) at offset 0x5F99 19776 bytes