Malicious PDF — malware analysis report

Static analysis result for SHA-256 a59c7c5974617f41…

MALICIOUS

PDF

83.6 KB Created: 2020-08-06 18:51:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 56832fc009aa46411425991c422b22cf SHA-1: fc7d856d55cddf3e90aaa54a811e0cb2f3d29dd7 SHA-256: a59c7c5974617f411e079b9c2d4c0318c312227f7e8136ab474e4384e1690ab6
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.ru/pify?keyword=technical+specification+of+steam+turbine+pdf'. Additionally, it exhibits a PDF link farm behavior, with numerous links to external PDFs, many hosted on cdn.shopify.com. The document body, though heavily obfuscated, contains the same URL as the malicious redirector, reinforcing the lure. The primary intent appears to be directing users to malicious infrastructure.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=technical+specification+of+steam+turbine+pdf
    • http://lazalit.hccbillings.org/uploads/1/3/1/4/131409090/1097836.pdf
    • http://files.bnmartialarts.com/uploads/1/3/1/3/131383657/lilina.pdf
    • http://files.smallbeautifulem.org/uploads/1/3/1/6/131607027/zamurevegazog_gonufudadikem_puvexop_vemenelot.pdf
    • http://vifaw.sterlingfaubel.com/uploads/1/3/2/7/132741555/waroxo-bumad.pdf
    • https://cdn.shopify.com/s/files/1/0437/3735/0305/files/kesajawojoxezi.pdf
    • https://cdn.shopify.com/s/files/1/0435/8828/8675/files/associer_deux_en_un_seul.pdf
    • https://cdn.shopify.com/s/files/1/0432/5467/7662/files/7740896714.pdf
    • https://cdn.shopify.com/s/files/1/0431/8052/3678/files/bavisodidumiximig.pdf
    • https://cdn.shopify.com/s/files/1/0428/3518/1734/files/37258317712.pdf
    • https://cdn.shopify.com/s/files/1/0429/7529/7689/files/robotics_engineering_books_download.pdf
    • https://cdn.shopify.com/s/files/1/0438/3889/8333/files/20747569234.pdf
    • https://cdn.shopify.com/s/files/1/0435/2580/0087/files/65555118730.pdf
    • https://cdn.shopify.com/s/files/1/0428/3331/3958/files/wiborerajevamazemo.pdf
    • https://cdn.shopify.com/s/files/1/0431/4103/8229/files/bomazebekegaludulowumoto.pdf
    • https://cdn.shopify.com/s/files/1/0432/8852/7013/files/mesegu.pdf
    • https://cdn.shopify.com/s/files/1/0427/4782/2236/files/zokesebagojigimu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000df39.bin
29101dccbdd26b917ab81d9bd75cbbd6cc1355d83463c73af800c3f6313db59d
pdf-font-stream PDF embedded font (sfnt) at offset 0xDF39 2912 bytes
font_01_sfnt_off0000e99f.bin
43fb00c4c249583589666dbe6cbf9bcca997706929badf0671af9a4b60a726a8
pdf-font-stream PDF embedded font (sfnt) at offset 0xE99F 5484 bytes
font_02_sfnt_off0000fc14.bin
0c635a3b5ff18c66f3db9683525ced4990fad26f400be22b4f322aca66f383ab
pdf-font-stream PDF embedded font (sfnt) at offset 0xFC14 14928 bytes
font_03_sfnt_off00012ac4.bin
a95eff378c135b1ab40d10b3cd1da1bafbc07f86005f57898d079c90d712ddbd
pdf-font-stream PDF embedded font (sfnt) at offset 0x12AC4 16204 bytes