Malicious PDF — malware analysis report

Static analysis result for SHA-256 dc05df03c44d01d7…

MALICIOUS

PDF

45.7 KB Created: 2020-08-05 07:18:10 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 58075e4314d31ced2159bee240c9488e SHA-1: 62b5432e1ae871f39c861c5305f6a5c42505d630 SHA-256: dc05df03c44d01d744b8bc081e6487ab2f774b677a05c0ab354cd0cc5a389f8e
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, many of which point to external resources. One critical heuristic firing indicates a malicious redirector link, specifically 'https://ttraff.ru/pify?keyword=capacitor+and+capacitance+pdf', which is designed to lead users to malicious content. The document body itself appears to be malformed or corrupted, but the presence of numerous links and the identified malicious redirector strongly suggest a phishing or redirection attack.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=capacitor+and+capacitance+pdf
    • http://files.freezerlink.com/uploads/1/3/0/8/130814288/6335778.pdf
    • http://files.uniquedobermans.com/uploads/1/3/2/6/132681556/3f1bfc6.pdf
    • http://files.trackingclubofma.com/uploads/1/3/0/8/130874210/3971527.pdf
    • http://files.connections203.com/uploads/1/3/2/7/132740186/zilux.pdf
    • https://cdn.shopify.com/s/files/1/0430/8520/1561/files/38194921946.pdf
    • https://cdn.shopify.com/s/files/1/0434/7278/1478/files/wuwumukilubemitolamoxosu.pdf
    • https://cdn.shopify.com/s/files/1/0437/3925/0853/files/systems_understanding_aid_9th_edition_solutions.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/zigomotixiwututorevibalu.pdf
    • https://cdn.shopify.com/s/files/1/0439/2812/5595/files/cambridge_checkpoint_science_3_peter_d_riley.pdf
    • https://cdn.shopify.com/s/files/1/0434/5528/3350/files/paruvaximotegijosasev.pdf
    • https://cdn.shopify.com/s/files/1/0431/1603/6249/files/dlink_dir655_manual.pdf
    • https://cdn.shopify.com/s/files/1/0432/2479/3245/files/7858431902.pdf
    • https://cdn.shopify.com/s/files/1/0436/2698/7680/files/54727249179.pdf
    • https://cdn.shopify.com/s/files/1/0433/8640/5029/files/john_deere_48_inch_mower_deck.pdf
    • https://cdn.shopify.com/s/files/1/0434/1488/0405/files/goripekijuretilobanawug.pdf
    • https://cdn.shopify.com/s/files/1/0434/0636/0725/files/vidakeminesiberuse.pdf
    • https://cdn.shopify.com/s/files/1/0432/0670/5316/files/english_learning_for_beginners.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006843.bin
f0782f0fe25adb1f00bab18b3b92c08f27fb43f88f3cc88a3717f7c83f9cf0b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x6843 4752 bytes
font_01_sfnt_off00007874.bin
f12072ec183b7e0ed926f3b47b40d22cbf3e02324365209e7ca54c1460edf03d
pdf-font-stream PDF embedded font (sfnt) at offset 0x7874 10540 bytes
font_02_sfnt_off00009bee.bin
9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x9BEE 4324 bytes