Malicious PDF — malware analysis report

Static analysis result for SHA-256 f3c670e9f615f140…

MALICIOUS

PDF

41.7 KB Created: 2020-08-29 16:09:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 60a8fb58fae6be6631b32ae769fb29c6 SHA-1: 677002df497af08a910f3b993fcc40380af3db83 SHA-256: f3c670e9f615f14006f140b8cb62c1345743ecd413c29f3a060eedcaa6ff47b8
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a mass external link farm, with one critical link pointing to a known malicious redirector at ttraff.ru. The document body, though heavily corrupted, contains the same URL, suggesting it's the intended lure. The primary attack pattern involves tricking the user into clicking this malicious link, likely leading to further compromise. No scripts were extracted, limiting the analysis of deeper payload delivery mechanisms.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=god+eater+resurrection+weapon+list
    • https://static.usrfiles.com/ugd/b8c837_f034b80f0d474d84949620da31371891.pdf
    • https://static.usrfiles.com/ugd/b8c837_6116d70b1f40463ba3c080b58084a790.pdf
    • https://static.usrfiles.com/ugd/b8c837_9f6098a780084613aac26b7d57425968.pdf
    • https://static.usrfiles.com/ugd/b8c837_27a1d5dae6d6492e9c161aa61f94b069.pdf
    • https://cdn.shopify.com/s/files/1/0430/1075/2663/files/lavugekufibemujixozef.pdf
    • https://cdn.shopify.com/s/files/1/0440/5601/9109/files/virafozifet.pdf
    • https://cdn.shopify.com/s/files/1/0434/7668/0870/files/43090641573.pdf
    • https://cdn.shopify.com/s/files/1/0428/8135/1839/files/6823829400.pdf
    • https://cdn.shopify.com/s/files/1/0430/6350/9146/files/minecraft_pc_game_demo.pdf
    • https://cdn.shopify.com/s/files/1/0433/3273/1038/files/simple_distribution_agreement_template_free.pdf
    • https://cdn.shopify.com/s/files/1/0431/9382/7485/files/var_candrive_age_16_yes__no.pdf
    • https://cdn.shopify.com/s/files/1/0429/5809/4495/files/ultimate_fashion_gift_guide.pdf
    • https://cdn.shopify.com/s/files/1/0437/3292/6616/files/wisconsin_dpi_license_lookup.pdf
    • https://cdn.shopify.com/s/files/1/0431/4162/8072/files/vavipezuzuluxifi.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000655a.bin
43add0a516141e8b881293ef5cfaf0bd08c4f69c5b9e45bca8c6ccd5d598c869
pdf-font-stream PDF embedded font (sfnt) at offset 0x655A 5192 bytes
font_01_sfnt_off00007727.bin
39f734a5498d374700a049448606d1de8fdba9a872fed74c977863c9a953c94d
pdf-font-stream PDF embedded font (sfnt) at offset 0x7727 10200 bytes