Malicious PDF — malware analysis report

Static analysis result for SHA-256 a90d8f5f5f9ffd5d…

MALICIOUS

PDF

41.2 KB Created: 2020-08-29 21:15:01 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 76abc0d8da42c5a09b06ea2f13acc4ba SHA-1: 3c9ff705b4cb247d5d8f43d6b8c30ff63e63e022 SHA-256: a90d8f5f5f9ffd5d812a4bfd624eeb1b0b33e5c4c7e65d1429cdc8a6776323e3
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains numerous embedded links, a common tactic for SEO poisoning and redirecting users to malicious sites. The primary heuristic indicates a malicious redirector link to 'ttraff.ru', which is likely used to serve further malicious content or phishing pages. The document body, though heavily obfuscated, contains text related to downloading PDFs and the malicious URL, reinforcing the lure.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=current+affairs+november+2018+pdf+download+in+english
    • https://cdn.shopify.com/s/files/1/0427/6020/8540/files/86239090232.pdf
    • https://cdn.shopify.com/s/files/1/0433/5602/9093/files/10625111149.pdf
    • https://cdn.shopify.com/s/files/1/0432/9983/1968/files/2628427671.pdf
    • https://cdn.shopify.com/s/files/1/0434/1887/8114/files/snow_leopard_iso.pdf
    • https://cdn.shopify.com/s/files/1/0430/6187/0741/files/guwimixuxoninomubodudere.pdf
    • https://static.usrfiles.com/ugd/b8c837_b2c7ec019d1240dc8bf1d6f825b46b2f.pdf
    • https://static.usrfiles.com/ugd/f80014_c4560c1e683e4663b473518f469900cc.pdf
    • https://static.usrfiles.com/ugd/b0b521_46a55c677909404ab48a73e79c6797aa.pdf
    • https://static.usrfiles.com/ugd/c0fca2_517d526776534e2982a2b87b3000ea7d.pdf
    • https://static.usrfiles.com/ugd/b8c837_09ff9eee10534719a34530a46cfcff34.pdf
    • https://static.usrfiles.com/ugd/6da380_2473418f763947ee99ae19e0a33b4f97.pdf
    • https://static.usrfiles.com/ugd/166c09_b60757d970574703acaf106dd7862c3e.pdf
    • https://static.usrfiles.com/ugd/b8c837_767516d29e734ebca158c269edd07f9c.pdf
    • https://static.usrfiles.com/ugd/b8c837_b8873021ca7949f9a9aab3c01abd3296.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000538f.bin
9ef9d01106e446201e037ab83660072b69ec19c6f490f99796d748a07beb996b
pdf-font-stream PDF embedded font (sfnt) at offset 0x538F 6172 bytes
font_01_sfnt_off00006879.bin
4111f2658653732dcd44faa808df83d356f857134a2d8017672d1291f206e405
pdf-font-stream PDF embedded font (sfnt) at offset 0x6879 10288 bytes
font_02_sfnt_off00008beb.bin
ee8afa51e50492bdf4d25b6b01818d2021856a0eb5271b70f188e6d094f25891
pdf-font-stream PDF embedded font (sfnt) at offset 0x8BEB 2832 bytes