Malicious PDF — malware analysis report

Static analysis result for SHA-256 d40cb7899d083f3e…

MALICIOUS

PDF

44.3 KB Created: 2020-08-31 04:59:59 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6c019c5673523485b3f303a99678679d SHA-1: 2c238fb6b812ffb49aa6274cf3cc2e5b7b19b266 SHA-256: d40cb7899d083f3ea35a83b817c9a7ad6699758f86ed6add7660371111a06a25
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file exhibits characteristics of a link farm, with numerous embedded URLs. One critical heuristic identified a malicious redirector link pointing to 'ttraff.ru', which is likely used to obscure the final destination or host malicious content. The document body, though heavily obfuscated, contains references to 'Fate grand order farming guide' and the redirector URL, suggesting a lure. The presence of a large number of external PDF links, many hosted on Shopify, further supports the SEO manipulation or content hosting aspect of the attack.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=fate+grand+order+farming+guide
    • https://static.usrfiles.com/ugd/2274a7_e932d3f96394403690361076c5755fa4.pdf
    • https://static.usrfiles.com/ugd/b8c837_1074e07e95a047e0bbf8a828a259661f.pdf
    • https://static.usrfiles.com/ugd/b11f6d_366513abb6154b5ca8c34c06e57eb96f.pdf
    • https://static.usrfiles.com/ugd/289c5e_d61155dd06da4929b847a2af09b0ce6e.pdf
    • https://static.usrfiles.com/ugd/b8c837_c93d21e7dd764e2ea686265d444ccb34.pdf
    • https://cdn.shopify.com/s/files/1/0428/1332/5471/files/petimakimejasijabogek.pdf
    • https://cdn.shopify.com/s/files/1/0433/5943/6951/files/milady_theory_workbook_answers_chapter_4.pdf
    • https://cdn.shopify.com/s/files/1/0431/4929/5776/files/coriolis_flow_meter.pdf
    • https://cdn.shopify.com/s/files/1/0428/8030/3263/files/harmonic_oscillator_wave_function.pdf
    • https://cdn.shopify.com/s/files/1/0437/7221/5448/files/custom_carbonless_order_forms.pdf
    • https://cdn.shopify.com/s/files/1/0438/3372/0992/files/wotek.pdf
    • https://cdn.shopify.com/s/files/1/0428/7938/5756/files/jebalatup.pdf
    • https://cdn.shopify.com/s/files/1/0460/6446/8123/files/rusty_lake_seasons_guide.pdf
    • https://cdn.shopify.com/s/files/1/0431/8501/2900/files/couch_to_5k_running_plan.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005a5d.bin
819e8692bbb044aa8f35850962e8629f0be0a8709a608f91ca59ed5152f1f525
pdf-font-stream PDF embedded font (sfnt) at offset 0x5A5D 4972 bytes
font_01_sfnt_off00006b36.bin
b2c252a3d1f92e659446c000e12320ebfba1cacf1aca628e444922353a8c2638
pdf-font-stream PDF embedded font (sfnt) at offset 0x6B36 10444 bytes
font_02_sfnt_off00008f14.bin
c487aa01613208473e3c0b892de3260687b9c0341624d6c76d95d7849508583e
pdf-font-stream PDF embedded font (sfnt) at offset 0x8F14 16088 bytes