Malicious PDF — malware analysis report

Static analysis result for SHA-256 aa08fef3f30c319d…

MALICIOUS

PDF

41.0 KB Created: 2020-08-08 05:56:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ffbe2a644d9b69c607e6b44ec20ab8e4 SHA-1: f0a4cfae299707e444349728e8f704d1d7f8ece4 SHA-256: aa08fef3f30c319d65632ab96eb4cb0c98c0c58c31609e9cafe275ba6e8f4637
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains numerous embedded links, with one specifically pointing to a known malicious redirector. The document body, though heavily obfuscated, contains the URL 'https://ttraff.ru/pify?keyword=difference+between+anode+and+cathode+pdf', which is flagged as malicious. The presence of a link farm suggests an attempt to distribute malicious content or engage in SEO poisoning. No scripts were extracted, but the primary attack vector appears to be social engineering via deceptive links.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=difference+between+anode+and+cathode+pdf
    • http://files.dhbeautybar.com/uploads/1/3/1/3/131397971/ridafifog-fufifovetane-zuvidobeles.pdf
    • http://files.visaofoundation.org/uploads/1/3/0/7/130740256/xederudimexobub.pdf
    • http://files.sweetpsdecor.com/uploads/1/3/1/4/131410736/9d405314dd50e.pdf
    • http://files.dreambigathletics.org/uploads/1/3/1/3/131398242/2b6964.pdf
    • https://cdn.shopify.com/s/files/1/0427/7580/6119/files/gedulukogos.pdf
    • https://cdn.shopify.com/s/files/1/0431/0063/5290/files/nezapanokod.pdf
    • https://cdn.shopify.com/s/files/1/0429/9456/5271/files/siwik.pdf
    • https://cdn.shopify.com/s/files/1/0433/2689/8344/files/9441858489.pdf
    • https://cdn.shopify.com/s/files/1/0428/3170/8316/files/95185519669.pdf
    • https://cdn.shopify.com/s/files/1/0439/2511/0952/files/the_kabbalah_tree_of_life_ritual_book.pdf
    • https://cdn.shopify.com/s/files/1/0430/1701/1353/files/bangla_boi_file.pdf
    • https://cdn.shopify.com/s/files/1/0431/8052/3678/files/birumazopuwijin.pdf
    • https://cdn.shopify.com/s/files/1/0437/7329/6789/files/psiphon_pro_handler_apk.pdf
    • https://cdn.shopify.com/s/files/1/0432/9242/6405/files/que_es_el_embarazo_y_sus_etapas.pdf
    • https://cdn.shopify.com/s/files/1/0432/9163/9968/files/satin_camisole_pattern.pdf
    • https://cdn.shopify.com/s/files/1/0429/7929/5383/files/retorolevedijine.pdf
    • https://cdn.shopify.com/s/files/1/0433/4449/4760/files/asturias_tab_download.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000062e8.bin
2c59ca5003c245e0b94310b637c4b9dc41c21b4609ff87b1cbb44463b8b2b36d
pdf-font-stream PDF embedded font (sfnt) at offset 0x62E8 5264 bytes
font_01_sfnt_off000074df.bin
b79a50c6a143338db78034ae96f2747721cd00f6589de0b7c51bce6f95a99175
pdf-font-stream PDF embedded font (sfnt) at offset 0x74DF 10036 bytes