Malicious PDF — malware analysis report

Static analysis result for SHA-256 de9647923a79f242…

MALICIOUS

PDF

54.5 KB Created: 2020-08-07 22:07:40 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 510682378f22628b3725c8ff65adb849 SHA-1: f6b91c61a155b159eb3acc981160e8d710d9c367 SHA-256: de9647923a79f2425a79710bdfeaabfe457b5892d1fea39afe942f6f789d6ab0
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, many of which point to domains associated with link farms and redirectors. The primary malicious URL identified is https://ttraff.ru/pify?keyword=environmental+carcinogenesis+pdf, which is flagged as a malicious redirector. The document body, though heavily obfuscated, also contains this URL, suggesting an attempt to disguise malicious activity as academic content. No scripts were extracted, limiting the analysis of direct execution capabilities.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=environmental+carcinogenesis+pdf
    • http://bepivig.lundecomputerconsulting.com/uploads/1/3/1/6/131606349/04e297b5db9ac.pdf
    • http://files.drclaytonmberger.com/uploads/1/3/0/9/130968934/fe8666c94c55.pdf
    • http://files.smisekfamilydentistry.com/uploads/1/3/1/3/131382955/1fe83797f1e31.pdf
    • http://files.delectanibble.com/uploads/1/3/1/4/131438217/boxokajikawevunadato.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/jedajuzosefowi.pdf
    • https://cdn.shopify.com/s/files/1/0438/8664/1304/files/28059752191.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/16779745642.pdf
    • https://cdn.shopify.com/s/files/1/0435/7767/1843/files/megasasuxerorevu.pdf
    • https://cdn.shopify.com/s/files/1/0431/5011/4978/files/nalizejowegixovosigar.pdf
    • https://cdn.shopify.com/s/files/1/0440/8141/4296/files/ps_plus_4life_space.pdf
    • https://cdn.shopify.com/s/files/1/0432/3681/9104/files/how_to_make_a_file.pdf
    • https://cdn.shopify.com/s/files/1/0430/7012/8277/files/74269242998.pdf
    • https://cdn.shopify.com/s/files/1/0437/2656/9633/files/62429268445.pdf
    • https://cdn.shopify.com/s/files/1/0431/9117/3282/files/fugigivujesuguwigero.pdf
    • https://cdn.shopify.com/s/files/1/0433/0065/1158/files/lixafitofagafamovagunawe.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009769.bin
92351dc3c7041b74970d58af5e4524dca95ff1397ff4d91a785e6929caf536ff
pdf-font-stream PDF embedded font (sfnt) at offset 0x9769 5492 bytes
font_01_sfnt_off0000aa0d.bin
e11b4ff3d05698322a17733600a74b48cdb1a5639eba74d4a947335b5451f3e0
pdf-font-stream PDF embedded font (sfnt) at offset 0xAA0D 10228 bytes