Malicious PDF — malware analysis report

Static analysis result for SHA-256 d683a85361d5603d…

MALICIOUS

PDF

58.5 KB Created: 2020-08-13 19:13:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6b0d12352548b86a7b08a77d89388335 SHA-1: 0b7ccda8594efe06d34b225a70de6935fd93cb56 SHA-256: d683a85361d5603dc7bbf39d639a54b8c542b52bf97277aea7891c4192a02103
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a high number of embedded links, many of which point to a link farm hosted on Shopify. One of these links, 'https://ttraff.ru/wb?keyword=5c%20of%20cinematography%20in%20tamil%20pdf', is identified as a malicious redirector. The document body, though heavily obfuscated, contains this URL, suggesting the primary intent is to redirect the user to malicious infrastructure. No scripts were extracted, limiting further analysis of execution chains.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wb?keyword=5c%20of%20cinematography%20in%20tamil%20pdf
    • http://files.visionandvisionloss.org/uploads/1/3/1/4/131406744/303761.pdf
    • http://buvorinup.mushinmovement.com/uploads/1/3/0/8/130814297/4560158.pdf
    • http://vukonupu.dyakcraft.com/uploads/1/3/1/4/131407535/46465f6a0.pdf
    • https://cdn.shopify.com/s/files/1/0432/0883/5229/files/vilenodigenoseg.pdf
    • https://cdn.shopify.com/s/files/1/0432/8439/8236/files/minecraft_pe_0._14._1.pdf
    • https://cdn.shopify.com/s/files/1/0436/3947/2288/files/autocad_excel_vba_tutorial.pdf
    • https://cdn.shopify.com/s/files/1/0434/0813/0213/files/cs_lewis_the_four_loves_free.pdf
    • https://cdn.shopify.com/s/files/1/0429/6769/5509/files/memuzumeziguliwesewaga.pdf
    • https://cdn.shopify.com/s/files/1/0433/5117/9423/files/binary_options_breakthrough_strategy.pdf
    • https://cdn.shopify.com/s/files/1/0433/7978/5886/files/30424850503.pdf
    • https://cdn.shopify.com/s/files/1/0438/8998/3640/files/worusawejakij.pdf
    • https://cdn.shopify.com/s/files/1/0430/3329/7058/files/48556867030.pdf
    • https://cdn.shopify.com/s/files/1/0428/5916/7900/files/1221987438.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/1261535930.pdf
    • https://cdn.shopify.com/s/files/1/0430/6285/3794/files/53496531775.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/21244882445.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off0000873d.bin
f7ac80a290be695568399c344f79a4a17b12b2a48f8d0d9ac26235edac03acd7
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x873D 21512 bytes
font_00_sfnt_off000074aa.bin
2da505c66ac55ccad6697c4a3223b808c85da59f303697aa22187f003a5303a8
pdf-font-stream PDF embedded font (sfnt) at offset 0x74AA 5520 bytes
font_02_sfnt_off0000b5a9.bin
23491183dcf2db217f19555a17c8aa064f0f0b3ef2aec42e960fb6d878aca8da
pdf-font-stream PDF embedded font (sfnt) at offset 0xB5A9 11520 bytes