Malicious PDF — malware analysis report

Static analysis result for SHA-256 aa753d3ceb0dcd50…

MALICIOUS

PDF

50.4 KB Created: 2020-08-24 21:27:28 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5f22a3a01a6fc70eac800dd08a9355bd SHA-1: 373e9d445dbd7d8cf593bb7783675413e8de411d SHA-256: aa753d3ceb0dcd505c8a6eb03f957336c8dedf4eb2b44354ecf516c6a6b0f07b
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.ru/pify?keyword=first+aid+certificate+template+uk'. This URL is presented within the document body, disguised as a template download. The file also exhibits characteristics of a link farm, with numerous embedded URLs, many of which point to PDF files hosted on various domains. No scripts were extracted from this sample, but the presence of the malicious redirector and the link farm structure strongly suggest a phishing or scam attempt.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=first+aid+certificate+template+uk
    • http://files.riseoverrunfit.com/uploads/1/3/2/7/132710748/537693.pdf
    • http://kizoro.ravishedbyhisbeauty.com/uploads/1/3/1/3/131383965/bixamuwi.pdf
    • http://files.thenewbraunfelsartleague.com/uploads/1/3/0/9/130969498/femofunosawimuz-jasanu-xolegapijude-jasemamugujimow.pdf
    • http://tatutem.langtechfun.com/uploads/1/3/0/8/130814017/domedejakobet_bumijamusume_topufutol.pdf
    • https://cdn.shopify.com/s/files/1/0433/4492/0734/files/86110456982.pdf
    • https://cdn.shopify.com/s/files/1/0432/5959/2864/files/ziguwedujilirovuv.pdf
    • https://cdn.shopify.com/s/files/1/0431/6643/3429/files/professional_business_analyst_cv_template.pdf
    • https://cdn.shopify.com/s/files/1/0431/4189/0209/files/tatkal_reservation_form.pdf
    • https://cdn.shopify.com/s/files/1/0428/5802/1027/files/diviradolojanepojugiduxuk.pdf
    • https://cdn.shopify.com/s/files/1/0433/1952/5534/files/speak_your_mind_in_writing_c2.pdf
    • https://cdn.shopify.com/s/files/1/0435/9330/2178/files/38755846453.pdf
    • https://cdn.shopify.com/s/files/1/0431/5440/7580/files/medical_laboratory_methods_and_tests.pdf
    • https://cdn.shopify.com/s/files/1/0433/8126/0440/files/15619126649.pdf
    • https://cdn.shopify.com/s/files/1/0432/7905/7056/files/10341681502.pdf
    • https://cdn.shopify.com/s/files/1/0434/0105/2327/files/dijemitaduvefisima.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000069a0.bin
0eac1552a6a0cc8d6d43e14f5c157d052ff2bf21460314f67a2c213e0a454e63
pdf-font-stream PDF embedded font (sfnt) at offset 0x69A0 6744 bytes
font_01_sfnt_off00007a87.bin
42aa09e45eaf627e5270443fbeb8c8bfcdb339fd9ebbf997d05e2cdcaff526e2
pdf-font-stream PDF embedded font (sfnt) at offset 0x7A87 4984 bytes
font_02_sfnt_off00008b7a.bin
f87fa96fbd7b044d69756a199051066bd13dc33bc6ff3afe91ae90af983ad7a7
pdf-font-stream PDF embedded font (sfnt) at offset 0x8B7A 10124 bytes
font_03_sfnt_off0000ae23.bin
a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f
pdf-font-stream PDF embedded font (sfnt) at offset 0xAE23 4324 bytes