Malicious PDF — malware analysis report

Static analysis result for SHA-256 ede82966b3fd3633…

MALICIOUS

PDF

42.2 KB Created: 2020-08-17 07:40:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6a3dbf8dc6c0994b0b6c3789e3d62387 SHA-1: 803623a4bd338ad7447bef6751aa04a4af9c2c24 SHA-256: ede82966b3fd3633ed07ee3d48d99b061039a13993bb85a7246c1f0105c24eae
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, many of which point to a link farm hosted on Shopify. One of the primary links directs to a known malicious redirector at 'ttraff.ru'. The document body, though heavily obfuscated, contains the same lure text and the malicious URL, suggesting an attempt to deceive users into clicking the link under the guise of research information. No scripts were extracted, and the primary malicious activity is link redirection.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=artificial+kidney+research+information
    • http://files.blockdata4good.com/uploads/1/3/0/9/130969656/selesuwimipapivi.pdf
    • http://nidujaz.speerbob.com/uploads/1/3/0/7/130738568/dinalusafoguran.pdf
    • http://files.everettqualitylandscaping.com/uploads/1/3/0/9/130969659/6686444.pdf
    • https://cdn.shopify.com/s/files/1/0433/4541/2254/files/78507860602.pdf
    • https://cdn.shopify.com/s/files/1/0446/5029/9555/files/css_box_sizing.pdf
    • https://cdn.shopify.com/s/files/1/0436/8610/1145/files/49459291513.pdf
    • https://cdn.shopify.com/s/files/1/0436/2820/0096/files/83680384822.pdf
    • https://cdn.shopify.com/s/files/1/0434/5567/6583/files/sezokorural.pdf
    • https://cdn.shopify.com/s/files/1/0431/2875/0241/files/vuxikenomabadakivilemar.pdf
    • https://cdn.shopify.com/s/files/1/0431/8298/1278/files/85599299704.pdf
    • https://cdn.shopify.com/s/files/1/0435/5624/1557/files/21813163706.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/dojezurin.pdf
    • https://cdn.shopify.com/s/files/1/0435/5820/7643/files/burn_iso_to_usb_mac.pdf
    • https://cdn.shopify.com/s/files/1/0433/4646/0830/files/85924246244.pdf
    • https://cdn.shopify.com/s/files/1/0429/5350/6969/files/afjet_afyonspor_forma_2019.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000064d2.bin
e0a67afa2cc682db6e3fef5eddeca2a9a74a36d56f6a8e07101f225aae1cfbdf
pdf-font-stream PDF embedded font (sfnt) at offset 0x64D2 5416 bytes
font_01_sfnt_off0000770b.bin
e14917643b7704b9821d07ef7b624a1a7db153b0ebc85d9b3d6f12fca52e3e11
pdf-font-stream PDF embedded font (sfnt) at offset 0x770B 10644 bytes