Malicious PDF — malware analysis report

Static analysis result for SHA-256 b2f13b343cd12238…

MALICIOUS

PDF

39.4 KB Created: 2020-09-01 03:43:20 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fe94aea702d89647a0cc0562fa320811 SHA-1: a33daf1f09a76a8e59cfad5424f1012ed4c97eb8 SHA-256: b2f13b343cd122380f4f207ac88da6b6341b270b6453b5e23cebab79b4e82994
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link farm designed to appear as a technical document, likely to trick users into clicking. The primary malicious link, https://ttraff.ru/wix?keyword=aws+cloudformation+template+format+error+unsupported+structure, is identified as a malicious redirector. The document body, though heavily obfuscated, contains references to the same technical error, reinforcing the lure. The presence of numerous benign-looking Shopify links suggests an attempt to mask the malicious redirector within a larger, seemingly legitimate link farm.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=aws+cloudformation+template+format+error+unsupported+structure
    • https://cdn.shopify.com/s/files/1/0436/8151/3622/files/2425270092.pdf
    • https://cdn.shopify.com/s/files/1/0436/8665/8213/files/jitadajezikopimugebigar.pdf
    • https://cdn.shopify.com/s/files/1/0431/8907/6117/files/jelimutifezep.pdf
    • https://static.usrfiles.com/ugd/3aca14_128df964369a44639d68f19865712238.pdf
    • https://static.usrfiles.com/ugd/61f964_3564ce980d64424ba80b143707162428.pdf
    • https://static.usrfiles.com/ugd/ca300b_303cdb77ad1d49158045ad8573150f4e.pdf
    • https://static.usrfiles.com/ugd/f46427_56314b1286a946c38e7ff23fc3d96cc2.pdf
    • https://static.usrfiles.com/ugd/b8c837_46b65b3cbfeb4ae888fd58478a344f59.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/60801944673.pdf
    • https://cdn.shopify.com/s/files/1/0428/0470/7491/files/biochemistry_by_h_stephen_stoker.pdf
    • https://cdn.shopify.com/s/files/1/0430/5004/1495/files/xupizuvulagojanonazutowag.pdf
    • https://cdn.shopify.com/s/files/1/0438/2621/7120/files/high_voltage_breakdown_tester.pdf
    • https://cdn.shopify.com/s/files/1/0432/9373/7110/files/histologie_de_l_appareil_urinaire.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005556.bin
e44a3d47b74470afa9f75d7266ea92d367f441439e154c4d82e06cf18f678b4e
pdf-font-stream PDF embedded font (sfnt) at offset 0x5556 5384 bytes
font_01_sfnt_off000067a0.bin
ef087ead9a8a95c5eb689fb39b1a1a07aad7700edf4225ac9ca27fccdc71ee99
pdf-font-stream PDF embedded font (sfnt) at offset 0x67A0 12456 bytes