Malicious PDF — malware analysis report

Static analysis result for SHA-256 e873b3cd3e15ac69…

MALICIOUS

PDF

60.0 KB Created: 2020-08-14 00:10:13 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8bf553f318791d77e97fcbfe2c8d7d3b SHA-1: 9b67c77348cb3ba1dd6c20a234d8495cfa039f9d SHA-256: e873b3cd3e15ac6988a81ee87478c8f069c440b336a0e2d1d42cc3820c031e0e
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.ru/pify?keyword=sales+rep+compensation+plan+template'. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded links, many of which are hosted on Shopify. The document body, though partially corrupted, contains the same URL as the redirector, suggesting it's the primary lure. The presence of multiple benign-looking Shopify links alongside the malicious one is a common tactic to obscure malicious intent.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=sales+rep+compensation+plan+template
    • http://gusodo.concealedcarryoflouisiana.com/uploads/1/3/2/6/132681352/8282875.pdf
    • http://files.celebrateblackhistory.ca/uploads/1/3/1/0/131071067/favibirilerenu.pdf
    • http://files.stephenjonesjewellers.com/uploads/1/3/0/7/130775102/6132942.pdf
    • http://files.anandoyoga.com/uploads/1/3/0/7/130738681/kipajatusasivoju.pdf
    • https://cdn.shopify.com/s/files/1/0432/0490/3073/files/35346348254.pdf
    • https://cdn.shopify.com/s/files/1/0431/1918/1978/files/11431815511.pdf
    • https://cdn.shopify.com/s/files/1/0431/4890/2556/files/zipanojovedina.pdf
    • https://cdn.shopify.com/s/files/1/0429/7159/4911/files/88714133642.pdf
    • https://cdn.shopify.com/s/files/1/0431/4506/8699/files/jaguxe.pdf
    • https://cdn.shopify.com/s/files/1/0433/8103/1061/files/74854914007.pdf
    • https://cdn.shopify.com/s/files/1/0435/2521/0263/files/94241658911.pdf
    • https://cdn.shopify.com/s/files/1/0435/9107/3947/files/21229505838.pdf
    • https://cdn.shopify.com/s/files/1/0434/0921/1557/files/xidojotutok.pdf
    • https://cdn.shopify.com/s/files/1/0431/6394/3067/files/lockout_tagout_removal_form.pdf
    • https://cdn.shopify.com/s/files/1/0436/9586/6024/files/xasegamatubom.pdf
    • https://cdn.shopify.com/s/files/1/0446/7880/7705/files/asclepius_wellness_new_product.pdf
    • https://cdn.shopify.com/s/files/1/0433/0386/2440/files/83810554192.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009ecd.bin
72494a6a7bb14993b0a40ceef3e679ba58cbaa1b98552fa980fb29237c9d7ec8
pdf-font-stream PDF embedded font (sfnt) at offset 0x9ECD 5180 bytes
font_01_sfnt_off0000b045.bin
792e9a746d0cb2a25ceaa4a540c6840edd300f807b6aee07f5cbad26bbefa328
pdf-font-stream PDF embedded font (sfnt) at offset 0xB045 10564 bytes
font_02_sfnt_off0000d465.bin
ea333071a1a431fec2d07139d845595be818e7abf3bc73c8b5078cc5a7539340
pdf-font-stream PDF embedded font (sfnt) at offset 0xD465 3640 bytes