Malicious PDF — malware analysis report

Static analysis result for SHA-256 f73861ef43683533…

MALICIOUS

PDF

59.9 KB Created: 2020-08-12 23:18:43 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6ea8bd39531de06df9b380d15f78fb7b SHA-1: b091c778999f2b9576e4fdee631626b8067a5b19 SHA-256: f73861ef43683533ea366d338aadf11206ba56d1c003b0dae004777d50f72c41
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a large number of embedded links, many pointing to domains associated with link farms and redirectors. The primary malicious link, https://ttraff.ru/wb?keyword=dna%20sequencing%20methods%20and%20applications%20pdf, is identified as a malicious redirector. The document body, though heavily obfuscated, also contains this URL, suggesting an attempt to lure users to malicious sites under the guise of academic content. No scripts were extracted, limiting the analysis of direct payload execution.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wb?keyword=dna%20sequencing%20methods%20and%20applications%20pdf
    • http://files.postcardsfromsurprisingplaces.com/uploads/1/3/1/4/131438459/niderinodi-videdo-vizazapi.pdf
    • http://files.revdonnalopez.com/uploads/1/3/1/4/131453907/7898940.pdf
    • http://files.sixdownonetogo.com/uploads/1/3/1/3/131383648/669440.pdf
    • http://files.education-projects.com/uploads/1/3/1/6/131637806/9f9ef2a3.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/nuxekenosagulowagegur.pdf
    • https://cdn.shopify.com/s/files/1/0435/2737/2964/files/dofisujuwamorexex.pdf
    • https://cdn.shopify.com/s/files/1/0428/8082/7558/files/urbana_sociologija.pdf
    • https://cdn.shopify.com/s/files/1/0432/2135/2606/files/korean_learning_books_free_download.pdf
    • https://cdn.shopify.com/s/files/1/0437/1064/4377/files/rikido.pdf
    • https://cdn.shopify.com/s/files/1/0434/1117/7626/files/fomezel.pdf
    • https://cdn.shopify.com/s/files/1/0431/8570/1019/files/acidoctose_diabtique_2020.pdf
    • https://cdn.shopify.com/s/files/1/0428/6627/8556/files/lonawiwukibuvaxidusogu.pdf
    • https://cdn.shopify.com/s/files/1/0433/6081/3208/files/bexaxozu.pdf
    • https://cdn.shopify.com/s/files/1/0440/8924/5861/files/telecharger_bob_et_bobette.pdf
    • https://cdn.shopify.com/s/files/1/0438/6645/6224/files/barabasi_the_formula.pdf
    • https://cdn.shopify.com/s/files/1/0438/3673/5645/files/ditelutoruzorifuza.pdf
    • https://cdn.shopify.com/s/files/1/0431/7233/1675/files/fikusexotejubipib.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000abed.bin
b9e4439f5dea24275c065c5e0e57d6f57f7388e96a811276cd4326d015af6404
pdf-font-stream PDF embedded font (sfnt) at offset 0xABED 5596 bytes
font_01_sfnt_off0000bece.bin
b64f70fb06ffa26213f808f45c0504330502b1132ba1bbbd4f70e483ab975b3a
pdf-font-stream PDF embedded font (sfnt) at offset 0xBECE 10516 bytes