Malicious PDF — malware analysis report

Static analysis result for SHA-256 bc8d3754fbf9b267…

MALICIOUS

PDF

50.2 KB Created: 2020-07-22 00:40:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7707cee881c32029914e9485a0f278f4 SHA-1: 1d2a03f1d4144ea004dd0fb90d64a30935f5f0b2 SHA-256: bc8d3754fbf9b2674c1333d45c3f3d7cc7275f9285cff073d924e367a5756c43
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains numerous embedded links, a technique often used to redirect users to malicious websites. One critical heuristic identified a link to a known malicious redirector, ttraff.ru, disguised with a keyword related to AI in medicine. Another heuristic flagged the document as a PDF link farm, with many external links, including one to cdn.shopify.com. The presence of these link farms and the malicious redirector suggests an attempt to distribute malware or phish for information.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wb?keyword=aplicaciones%20de%20la%20inteligencia%20artificial%20en%20medicina%20pdf
    • http://files.hansroegelearchitect.com/uploads/1/3/1/4/131408581/wizikupopofafurularu.pdf
    • http://files.wayfaringbride.com/uploads/1/3/0/8/130813714/d5f7e62969d82ad.pdf
    • http://files.sidneyshelbychamber.com/uploads/1/3/2/6/132696145/fidujo_zuvetare.pdf
    • https://cdn.shopify.com/s/files/1/0431/6046/9660/files/1039092330.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/38935964995.pdf
    • https://cdn.shopify.com/s/files/1/0437/8935/3120/files/33370189416.pdf
    • https://cdn.shopify.com/s/files/1/0430/7078/3645/files/72677655847.pdf
    • https://velefibilon.files.wordpress.com/2020/06/mozuxigidamatepupo.pdf
    • https://kadipuxosika.files.wordpress.com/2020/06/16488582901.pdf
    • https://fazupisis.files.wordpress.com/2020/06/54184487439.pdf
    • https://mapobaz.files.wordpress.com/2020/07/82648692787.pdf
    • https://cdn.shopify.com/s/files/1/0432/3740/8936/files/mazijojafokitetogubegumis.pdf
    • https://cdn.shopify.com/s/files/1/0431/0486/2375/files/putaguvujenazosef.pdf
    • https://cdn.shopify.com/s/files/1/0433/9266/3702/files/20268613567.pdf
    • https://cdn.shopify.com/s/files/1/0432/9200/0422/files/daworufuluxeper.pdf
    • https://cdn.shopify.com/s/files/1/0429/2562/1404/files/wamasewiliduw.pdf
    • https://cdn.shopify.com/s/files/1/0438/5384/0534/files/wafobepaziminojafusurarej.pdf
    • https://cdn.shopify.com/s/files/1/0435/8628/9832/files/61381004738.pdf
    • https://cdn.shopify.com/s/files/1/0429/0877/8663/files/9417875502.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008288.bin
1370af885631c3cc785217437c7b175537598350009bcdaacaaec79b096ba0a0
pdf-font-stream PDF embedded font (sfnt) at offset 0x8288 5252 bytes
font_01_sfnt_off00009440.bin
e6db23b06aa78e107f589219f18699725fd3830ed50300304f9e2ffc9b105962
pdf-font-stream PDF embedded font (sfnt) at offset 0x9440 11360 bytes