Malicious PDF — malware analysis report

Static analysis result for SHA-256 cb4c65169425112f…

MALICIOUS

PDF

42.0 KB Created: 2020-08-13 00:00:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7dd85fb24d5edc0e8a16b7107b18d196 SHA-1: 826278f9f110790c0bebcd45b51354f7dd1fa725 SHA-256: cb4c65169425112fa15c22eaaff3f36083e13400fba6dad3aa43e1f444e1b800
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a link that redirects to a known malicious domain, ttraff.ru. This domain is used in conjunction with a keyword-stuffed URL, suggesting a SEO poisoning or link farm tactic to lure victims. The document body, though heavily obfuscated, contains the same URL, reinforcing the malicious intent. The presence of numerous other links, many pointing to Shopify domains, further indicates a link farm strategy.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=attendance+management+system+project+in+java+with+source+code+pdf
    • http://vepusa.joelmiddleton.com/uploads/1/3/0/8/130813557/6657075.pdf
    • http://posax.beneath1000skies.com/uploads/1/3/1/6/131607163/vebobawuvupo_vulugexiropef_zilezesanemuja.pdf
    • http://files.lindabierymusic.com/uploads/1/3/0/7/130740504/8696593.pdf
    • https://cdn.shopify.com/s/files/1/0431/6590/9160/files/fosewoxovejojalela.pdf
    • https://cdn.shopify.com/s/files/1/0438/2323/5232/files/21555553492.pdf
    • https://cdn.shopify.com/s/files/1/0445/5153/6799/files/mysqldump_remote_database.pdf
    • https://cdn.shopify.com/s/files/1/0433/6877/5841/files/70907717485.pdf
    • https://cdn.shopify.com/s/files/1/0437/9443/2161/files/razor_mini_choppers.pdf
    • https://cdn.shopify.com/s/files/1/0435/5679/8613/files/munejarujezegigujuvopuki.pdf
    • https://cdn.shopify.com/s/files/1/0435/4582/1333/files/99892102753.pdf
    • https://cdn.shopify.com/s/files/1/0433/8555/3061/files/xazatuxerawutax.pdf
    • https://cdn.shopify.com/s/files/1/0437/3997/1736/files/22273921138.pdf
    • https://cdn.shopify.com/s/files/1/0432/2341/6987/files/lupar.pdf
    • https://cdn.shopify.com/s/files/1/0431/4906/6397/files/59588685931.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006214.bin
cc3027c417de81a40241d538c620fe44656bff95d1cd7532fe2ddfc352906418
pdf-font-stream PDF embedded font (sfnt) at offset 0x6214 5856 bytes
font_01_sfnt_off000075f7.bin
02dd8518e93bd490306f7c793ab14b9f4ee7f9848e428965e92ce24d3836c873
pdf-font-stream PDF embedded font (sfnt) at offset 0x75F7 10820 bytes