Malicious PDF — malware analysis report

Static analysis result for SHA-256 a69a75ae5a617b10…

MALICIOUS

PDF

113.5 KB Created: 2020-08-29 20:56:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8dc89667317dfc8095ef299b218b49cd SHA-1: 433f85d3845a454060e4227fcc15cec0477c0eb2 SHA-256: a69a75ae5a617b10f8d6a2a422fbbd911e74e754c2c1bb2f7cc38222be65684d
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link pointing to 'https://ttraff.ru/wix?keyword=cuaderno+de+trabajo+matematicas+1+primaria'. It also contains a PDF link farm heuristic, with many links pointing to shopify.com, including 'https://cdn.shopify.com/s/files/1/0435/2330/9727/files/canape_vector.pdf'. The document body, though heavily corrupted, contains the same malicious URL and appears to be a lure related to educational material.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=cuaderno+de+trabajo+matematicas+1+primaria
    • https://cdn.shopify.com/s/files/1/0435/2330/9727/files/canape_vector.pdf
    • https://cdn.shopify.com/s/files/1/0434/2651/3047/files/squire_bouree_sheet_music.pdf
    • https://cdn.shopify.com/s/files/1/0439/3641/5899/files/nuzekixitozegefizo.pdf
    • https://cdn.shopify.com/s/files/1/0434/0521/3847/files/sovebape.pdf
    • https://cdn.shopify.com/s/files/1/0464/9022/2744/files/41996798836.pdf
    • https://cdn.shopify.com/s/files/1/0433/3119/0952/files/daughtry_what_about_now.pdf
    • https://cdn.shopify.com/s/files/1/0434/4319/1969/files/intermatic_st01_manual.pdf
    • https://static.usrfiles.com/ugd/b8c837_f9e2b75fe5cf49abb033ac07ce16b3c0.pdf
    • https://static.usrfiles.com/ugd/b8c837_8ce3de2a0dbe44b98f7ad2a3844927c0.pdf
    • https://cdn.shopify.com/s/files/1/0436/8600/2838/files/73146623413.pdf
    • https://cdn.shopify.com/s/files/1/0432/9727/6064/files/3d_anaglyph_video_maker_free.pdf
    • https://cdn.shopify.com/s/files/1/0469/0067/4720/files/34684990447.pdf
    • https://cdn.shopify.com/s/files/1/0437/7346/0641/files/mezotezexakezifapafus.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00017428.bin
64a18183fd39bc0c68dccfb68599f6479f70e802c6f2af9b18551697cac767d6
pdf-font-stream PDF embedded font (sfnt) at offset 0x17428 2224 bytes
font_01_sfnt_off00017da9.bin
7cacf3b54c6ba4ce8ff28874e32a09a9254b1013f3ba5efc4eb3c97cfc5019db
pdf-font-stream PDF embedded font (sfnt) at offset 0x17DA9 5360 bytes
font_02_sfnt_off00018fcb.bin
534037cd1632b0ed1edebe09e5bd2baee0fafca6c8f5bb02453bd56b8b5de1f1
pdf-font-stream PDF embedded font (sfnt) at offset 0x18FCB 11868 bytes