Malicious PDF — malware analysis report

Static analysis result for SHA-256 f9640de74f8de19d…

MALICIOUS

PDF

41.8 KB Created: 2020-08-11 01:50:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7d1a042a5f29667cbe9e126becf70a53 SHA-1: be0de08d7bded08c4a2cb8e28d9947904d1102fa SHA-256: f9640de74f8de19d1fb7a61cf6338f042a62b8637c8ab30e51b78369a6af5e9b
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a mass of external links, including one pointing to a known malicious redirector at 'https://ttraff.ru/pify?keyword=arkham+city+walkthrough+pdf'. The document body, though heavily obfuscated, also contains this URL, suggesting the primary purpose is to redirect the user to malicious infrastructure. The presence of numerous other PDF links, many hosted on Shopify, indicates a link farm strategy to improve search engine ranking for malicious content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=arkham+city+walkthrough+pdf
    • http://files.danieljohnmenswear.co.uk/uploads/1/3/1/1/131164097/pidixuliginenibukino.pdf
    • http://files.mullerandson.com/uploads/1/3/2/6/132695682/9579d1be2a4a3.pdf
    • http://files.talentzambiausa.com/uploads/1/3/0/7/130776558/zatovol.pdf
    • http://files.arthurkirmss.net/uploads/1/3/1/6/131606056/fugaxajawevul.pdf
    • https://cdn.shopify.com/s/files/1/0433/9302/4151/files/15014407757.pdf
    • https://cdn.shopify.com/s/files/1/0430/7920/5018/files/banejolebilapupex.pdf
    • https://cdn.shopify.com/s/files/1/0433/2398/1979/files/relupubelabadigolewore.pdf
    • https://cdn.shopify.com/s/files/1/0433/8676/5475/files/april_current_affairs_2020_wifistudy.pdf
    • https://cdn.shopify.com/s/files/1/0433/4790/2629/files/23987449617.pdf
    • https://cdn.shopify.com/s/files/1/0430/3018/4098/files/6585442337.pdf
    • https://cdn.shopify.com/s/files/1/0435/3867/7924/files/lupevujudixesobok.pdf
    • https://cdn.shopify.com/s/files/1/0429/2267/2284/files/webovuvoberab.pdf
    • https://cdn.shopify.com/s/files/1/0431/7147/9713/files/85707434664.pdf
    • https://cdn.shopify.com/s/files/1/0431/4116/9303/files/ruvikodisutetovipogan.pdf
    • https://cdn.shopify.com/s/files/1/0429/4973/8650/files/67758977662.pdf
    • https://cdn.shopify.com/s/files/1/0433/5193/3078/files/nujuxu.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006530.bin
e507930daf58bf36c0703fd2e373725a284ff8d86e7fc6e901b770266c7157cc
pdf-font-stream PDF embedded font (sfnt) at offset 0x6530 5636 bytes
font_01_sfnt_off00007852.bin
19c54fc4c3f68ad77d73abbd36aed0c5e5e31b3b3c6ef4030639d16a879f5d9a
pdf-font-stream PDF embedded font (sfnt) at offset 0x7852 9968 bytes