Malicious PDF — malware analysis report

Static analysis result for SHA-256 f64c2fdd438debd3…

MALICIOUS

PDF

50.3 KB Created: 2020-08-20 20:46:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5a48ff34518a43007384cc61e89d6e38 SHA-1: 1259c3feef1fda1ee8fcd42503bb0d05cf16ba22 SHA-256: f64c2fdd438debd3cb31080ad736c538028575fb255031c182e190e1df14ffdf
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains numerous embedded links, with a critical heuristic identifying it as a malicious redirector link farm. One of the primary URLs, 'https://ttraff.ru/pify?keyword=army+new+uniform+acu', is flagged as malicious. The document body itself is heavily obfuscated but contains references to this URL. The presence of many external links, including those hosted on Shopify, suggests an attempt to manipulate search engine results or distribute malicious content through a large number of seemingly benign-looking documents.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=army+new+uniform+acu
    • http://files.danhegstad.com/uploads/1/3/1/3/131378950/ea9a89e56256f.pdf
    • http://xesij.trinityjamestown.com/uploads/1/3/0/7/130738765/1ed3b4310ff1.pdf
    • http://sewuzilaz.pamserrawenz.com/uploads/1/3/0/9/130969742/xenefowad.pdf
    • http://files.halovolleyball.com/uploads/1/3/1/3/131398479/tisumitaradoziviza.pdf
    • https://cdn.shopify.com/s/files/1/0431/4929/5776/files/jeturirisubatavedexakez.pdf
    • https://cdn.shopify.com/s/files/1/0438/5911/6182/files/biblical_names_and_meaning.pdf
    • https://cdn.shopify.com/s/files/1/0433/6952/9509/files/88480776634.pdf
    • https://cdn.shopify.com/s/files/1/0432/4065/2960/files/70390035438.pdf
    • https://cdn.shopify.com/s/files/1/0437/4868/8033/files/achilles_tendonitis_exercise.pdf
    • https://cdn.shopify.com/s/files/1/0449/4472/0040/files/blood_pressure_guide_nhs.pdf
    • https://cdn.shopify.com/s/files/1/0433/3443/4969/files/bzip2_manual_page.pdf
    • https://cdn.shopify.com/s/files/1/0438/1789/4050/files/botibubamasiz.pdf
    • https://cdn.shopify.com/s/files/1/0437/0392/6952/files/61850088575.pdf
    • https://cdn.shopify.com/s/files/1/0429/5147/5366/files/32905273738.pdf
    • https://cdn.shopify.com/s/files/1/0435/4854/1087/files/70516705184.pdf
    • https://cdn.shopify.com/s/files/1/0435/6295/8997/files/35066067174.pdf
    • https://cdn.shopify.com/s/files/1/0438/9765/1352/files/runizutetodejumiwan.pdf
    • https://cdn.shopify.com/s/files/1/0441/4255/9384/files/peperibofovu.pdf
    • https://cdn.shopify.com/s/files/1/0431/7085/7124/files/82210217974.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007e24.bin
97611af12fa55de2ad7e58a78436075a3ba8f7ba02e9692e7cbd68d5f5f89394
pdf-font-stream PDF embedded font (sfnt) at offset 0x7E24 5000 bytes
font_01_sfnt_off00008f1e.bin
9074eb9ac76ecdecd351425a488379fc39a3ae454043357a3a74cad336988d5e
pdf-font-stream PDF embedded font (sfnt) at offset 0x8F1E 14636 bytes