Malicious PDF — malware analysis report

Static analysis result for SHA-256 cb2b351db483d9ec…

MALICIOUS

PDF

109.6 KB Created: 2020-08-08 16:16:19 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 42668bea4fa339afd661bcec0d4a0952 SHA-1: 35ab566e2905e1f5b89ac24df21754c1008e9e16 SHA-256: cb2b351db483d9ec774503a5347bcf46e939425f92c341bf872bccc5265983d5
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains numerous embedded links, with a critical heuristic identifying a link to a known malicious redirector at https://ttraff.ru/pify. This suggests the document is part of an SEO-based link farm designed to drive traffic to malicious infrastructure. The document body, though heavily obfuscated, contains the target search query and the redirector URL, reinforcing the malicious intent. No scripts were extracted, limiting the analysis of specific execution behaviors.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=chomsky+syntactic+structures+1957+pdf
    • http://files.catholicapostolatecenter.org/uploads/1/3/1/8/131872017/vazika.pdf
    • http://files.thegoodlifeheatons.com/uploads/1/3/1/0/131070602/91c3ad5a2bc.pdf
    • http://files.japanischerweihnachtsmarktberlin.com/uploads/1/3/0/7/130738837/piletuteniratusop.pdf
    • https://cdn.shopify.com/s/files/1/0441/1670/5432/files/29477287466.pdf
    • https://cdn.shopify.com/s/files/1/0432/1024/4256/files/tolilo.pdf
    • https://cdn.shopify.com/s/files/1/0431/8347/2802/files/vipejajimaleduzefipatuja.pdf
    • https://cdn.shopify.com/s/files/1/0430/8421/8521/files/bogafigisolubuvinewu.pdf
    • https://cdn.shopify.com/s/files/1/0433/4508/4574/files/dilibudasuwopoziv.pdf
    • https://cdn.shopify.com/s/files/1/0433/3928/4645/files/rusimudawirorez.pdf
    • https://cdn.shopify.com/s/files/1/0428/7230/7875/files/wogigaga.pdf
    • https://cdn.shopify.com/s/files/1/0432/8092/4837/files/92050231649.pdf
    • https://cdn.shopify.com/s/files/1/0448/9238/9531/files/active_and_passive_causative_exercises.pdf
    • https://cdn.shopify.com/s/files/1/0437/0422/1846/files/46906107224.pdf
    • https://cdn.shopify.com/s/files/1/0429/7215/1959/files/soal_angka_penting.pdf
    • https://cdn.shopify.com/s/files/1/0433/3584/3994/files/11559872797.pdf
    • https://cdn.shopify.com/s/files/1/0437/7041/3207/files/fobipadonakejujatigibaze.pdf
    • https://cdn.shopify.com/s/files/1/0434/0491/8941/files/26122788855.pdf
    • https://cdn.shopify.com/s/files/1/0435/2324/4191/files/84994414839.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00014e85.bin
4e7f0b8833f38e951d226fcfde82d72f0903093c820e47e512382734a071afc6
pdf-font-stream PDF embedded font (sfnt) at offset 0x14E85 5516 bytes
font_01_sfnt_off000161a3.bin
ac3b01e5f84905aff67555249b1316eaf35dba652170d7da085c901e8f9fdcf1
pdf-font-stream PDF embedded font (sfnt) at offset 0x161A3 5848 bytes
font_02_sfnt_off00017572.bin
4703f32fdd11eff9663681d80934d7a5444f128fc6a0fcda75a4059cc2e6eadf
pdf-font-stream PDF embedded font (sfnt) at offset 0x17572 16696 bytes