Malicious PDF — malware analysis report

Static analysis result for SHA-256 facb89cd2a2d36ed…

MALICIOUS

PDF

43.8 KB Created: 2020-08-05 15:49:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5cf5f0cc48c597a10c90bf419f370dc2 SHA-1: 69c19add3f1bb531a1afd8b9c843361c7f02bf2f SHA-256: facb89cd2a2d36ed38e8389ae459e12cac933633f32cbf4296107599641b3a9d
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, many pointing to Shopify domains, but one critical link directs to a known malicious redirector at 'ttraff.ru'. This suggests a link farm or SEO poisoning tactic to distribute malicious content. The document body, though heavily garbled, contains text related to an audit report and the malicious URL, reinforcing the lure. No scripts were extracted, but the primary attack vector appears to be social engineering via a deceptive document and a malicious link.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=relat%25C3%25B3rio+de+auditoria+interna+exemplo+pdf
    • http://files.outboardpros.com/uploads/1/3/1/4/131407547/95bd854f.pdf
    • http://files.mygurlstuff-jewelry.com/uploads/1/3/1/1/131164546/e4741389.pdf
    • http://files.marydarwalljewelry.com/uploads/1/3/1/8/131856318/mirej_ridebabi.pdf
    • http://files.margierossi.com/uploads/1/3/1/4/131453206/f2cdf9.pdf
    • https://cdn.shopify.com/s/files/1/0430/3929/3593/files/71820794370.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/3152232763.pdf
    • https://cdn.shopify.com/s/files/1/0431/5709/4551/files/verifone_ruby_2.pdf
    • https://cdn.shopify.com/s/files/1/0439/9307/1774/files/17584809172.pdf
    • https://cdn.shopify.com/s/files/1/0433/6995/5486/files/67222863004.pdf
    • https://cdn.shopify.com/s/files/1/0429/9515/5105/files/vusilapogadesuniku.pdf
    • https://cdn.shopify.com/s/files/1/0430/3021/6855/files/77266525890.pdf
    • https://cdn.shopify.com/s/files/1/0430/9765/3397/files/pudofisubetosowidivuvewob.pdf
    • https://cdn.shopify.com/s/files/1/0431/9284/4448/files/how_to_delete_groove_music.pdf
    • https://cdn.shopify.com/s/files/1/0437/6412/1749/files/mezober.pdf
    • https://cdn.shopify.com/s/files/1/0433/6612/1623/files/21483722724.pdf
    • https://cdn.shopify.com/s/files/1/0433/4541/2245/files/aacn_procedure_manual_for_critical_care.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005dbf.bin
fdbc759109672b6c0e8cd1651f059ab8c270a88e53aede7fdd992db166a49d7c
pdf-font-stream PDF embedded font (sfnt) at offset 0x5DBF 5104 bytes
font_01_sfnt_off00006eca.bin
621db48bec777780caf8a20868114cc4a95cd1cff3e6de87527be4a92822f59d
pdf-font-stream PDF embedded font (sfnt) at offset 0x6ECA 11464 bytes
font_02_sfnt_off00009175.bin
0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333
pdf-font-stream PDF embedded font (sfnt) at offset 0x9175 4324 bytes