Malicious PDF — malware analysis report

Static analysis result for SHA-256 dc413805f5bca446…

MALICIOUS

PDF

43.2 KB Created: 2020-08-19 04:47:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 788fd2fcdd839f8a73bdcc50eb1029bb SHA-1: f54ab0621a83c55fc274c2d19a75b13c80edd895 SHA-256: dc413805f5bca44600cd1221d90b20e86763b234120526ce4d50a68dcabba5e2
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing for PDF_MALICIOUS_REDIRECTOR_LINK, indicating it points to malicious infrastructure. Additionally, PDF_SEO_LINK_FARM indicates a large number of external PDF links, likely for SEO manipulation or to hide malicious content. The primary malicious URL identified is https://ttraff.ru/pify?keyword=cnco+pretend+mp4, which is used in conjunction with a large number of benign-looking Shopify links. The document body contains garbled text but includes the malicious URL and several Shopify URLs.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=cnco+pretend+mp4
    • http://files.sjhsasb.com/uploads/1/3/2/8/132814463/dafukimobalafemoki.pdf
    • http://numepar.tlcnashville.org/uploads/1/3/1/3/131384281/3784329.pdf
    • https://cdn.shopify.com/s/files/1/0430/4686/3005/files/bailey_and_love_surgery_book_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0437/4993/3208/files/96353113042.pdf
    • https://cdn.shopify.com/s/files/1/0429/8440/7199/files/brushless_alternator_seminar.pdf
    • https://cdn.shopify.com/s/files/1/0431/6217/3604/files/99198658637.pdf
    • https://cdn.shopify.com/s/files/1/0434/7841/7558/files/peligu.pdf
    • https://cdn.shopify.com/s/files/1/0439/7950/5822/files/aashiqui_2_full_picture.pdf
    • https://cdn.shopify.com/s/files/1/0432/9275/4076/files/automobile_design_engineering.pdf
    • https://cdn.shopify.com/s/files/1/0432/3006/8894/files/78700772400.pdf
    • https://cdn.shopify.com/s/files/1/0447/9765/7248/files/39703003443.pdf
    • https://cdn.shopify.com/s/files/1/0430/8143/3242/files/51460014139.pdf
    • https://cdn.shopify.com/s/files/1/0440/2829/7381/files/sound_insulation_materials.pdf
    • https://cdn.shopify.com/s/files/1/0432/9462/1862/files/wururegofodexuxikinoz.pdf
    • https://cdn.shopify.com/s/files/1/0434/8359/4917/files/74565093696.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004a74.bin
7684162b5dd8ecb9cf3bae9110663b53b4a08ec53482d4734748f3e0b531a60d
pdf-font-stream PDF embedded font (sfnt) at offset 0x4A74 4792 bytes
font_01_sfnt_off00005aa3.bin
4b1f2219c54756357e6d359238b8c5401c854f6fa61fc0f22466bc7f9c64523f
pdf-font-stream PDF embedded font (sfnt) at offset 0x5AA3 13908 bytes
font_02_sfnt_off00008255.bin
1df41416ece054d3cca32f135e48dc95f4d9c8a2bff4ba4edba1d14e21aabef6
pdf-font-stream PDF embedded font (sfnt) at offset 0x8255 18776 bytes