Malicious PDF — malware analysis report

Static analysis result for SHA-256 f3e826577f463a58…

MALICIOUS

PDF

39.5 KB Created: 2020-08-31 03:17:19 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 06043f9c35172882e32b96fbae4792e4 SHA-1: 6bb002f400f0fcc452093cbb191a73f09c8ac9d5 SHA-256: f3e826577f463a582ee4e8d0d595e307037de702f7d85c0ee1db405aa66339ce
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 User Execution: Malicious File

The PDF file contains a link to a redirector URL, which is a common tactic for distributing malicious content. The document body, though heavily obfuscated, contains text related to a game codex and a URL that appears to be a lure for downloading a PDF. The presence of a "download button" heuristic further supports the idea that the document is designed to trick the user into clicking a link. The primary malicious URL identified is ttraff.ru, which is likely used to redirect to the actual payload.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=astra+militarum+codex+pdf+download
    • https://static.usrfiles.com/ugd/b8c837_4a4f14071a4c426f88c4eb5238b1e70f.pdf
    • https://static.usrfiles.com/ugd/e745be_4c7d147b32e7477880e75534a8e0001f.pdf
    • https://static.usrfiles.com/ugd/3bca44_db533f0f5c144e789e3a36fe2139f246.pdf
    • https://static.usrfiles.com/ugd/b8c837_3a53140c68e54a268f467692d0803f34.pdf
    • https://static.usrfiles.com/ugd/8b49c6_e53c8091205e4a3989bcf1760a5dfcc6.pdf
    • https://static.usrfiles.com/ugd/0d2908_22f6f86637a74c4291b1c6f419c25359.pdf
    • https://static.usrfiles.com/ugd/47b1e8_0f70dbf76861425e909c2a4ea40090ca.pdf
    • https://cdn.shopify.com/s/files/1/0434/4794/3330/files/beginner_country_line_dance_step_sheets.pdf
    • https://cdn.shopify.com/s/files/1/0434/5076/1377/files/banting_bread_recipe.pdf
    • https://cdn.shopify.com/s/files/1/0431/2973/3282/files/70555310531.pdf
    • https://cdn.shopify.com/s/files/1/0450/9771/3829/files/add_text_to_a_file_online_free.pdf
    • https://static.usrfiles.com/ugd/b910ae_60deca2b574e43be8141b714250cdc1b.pdf
    • https://static.usrfiles.com/ugd/87d215_a5b4f427857243e498ea7daa9247ff76.pdf
    • https://static.usrfiles.com/ugd/12daa7_949a5842cf5346d488f5cd5562c0e000.pdf
    • https://static.usrfiles.com/ugd/b8c837_a780ce450f614092ad228dac8e8e6997.pdf
    • https://static.usrfiles.com/ugd/b8c837_2fd7f8ff25d8455e83d95834c6718109.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004b60.bin
f20a75df2876ae409aa0d0c6f4c79c33568b97463aed2902edd94bfed1252331
pdf-font-stream PDF embedded font (sfnt) at offset 0x4B60 4648 bytes
font_01_sfnt_off00005b9d.bin
4b6b10f4c3f477671a74579cf7f3bfe2b1fca1de443da3a16edc26c41e4634d7
pdf-font-stream PDF embedded font (sfnt) at offset 0x5B9D 5448 bytes
font_02_sfnt_off00006e1e.bin
e3711f7b8a0d449178c03f680fb83303a1dd411bf763dab3bf85132698ed3a3d
pdf-font-stream PDF embedded font (sfnt) at offset 0x6E1E 10032 bytes