Malicious PDF — malware analysis report

Static analysis result for SHA-256 1a8dabe7b2c3c610…

MALICIOUS

PDF

42.0 KB Created: 2020-09-16 17:40:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 55355f63e0333f913895fa9d5b6f5fc4 SHA-1: d86f70c57fa169d43dd34925f8e4c88a50942fc5 SHA-256: 1a8dabe7b2c3c61089e6bced41e178e8a8516ab8fd2f857e6001b2af5029b528
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, many of which point to suspicious domains and are likely part of a link farm designed for SEO manipulation. One critical heuristic identified a link to known malicious redirector infrastructure. The document body, though partially corrupted, contains text related to a 'leveling guide' and the URL https://ttraff.club/wix?keyword=leveling+guide+85-90, suggesting a lure to a malicious site. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=leveling+guide+85-90
    • http://jagitavus.christopherwongld.com/uploads/1/3/2/6/132681602/bivajesosubidog-lisuxofazumo-zemiwena.pdf
    • http://files.designforequity.org/uploads/1/3/0/9/130968921/7c74512e.pdf
    • http://xozala.midwestaaoe.com/uploads/1/3/2/6/132681824/pojifufinu.pdf
    • http://files.crystal-river-healing.com/uploads/1/3/0/8/130813982/9a877e15c77612.pdf
    • http://lowagojo.friendsofraymondjames.org/uploads/1/3/2/8/132815296/buvat_xateve_dulile.pdf
    • https://6f775e63-0572-4a21-9a42-1013e3d440fc.filesusr.com/ugd/3835dd_5689e07dca3347d1b179bca56342b994.pdf?index=true
    • https://24a0b585-5f16-462a-9400-1b988becb3d8.filesusr.com/ugd/b42fd6_88138ae4ddc24b6e81113d3f0fae483e.pdf?index=true
    • https://3d2736fd-dcc4-46bf-8592-c8c90f271b97.filesusr.com/ugd/738632_b32bad23104e4cbf96b8a6af9899eeb4.pdf?index=true
    • https://56c137de-7c20-4aec-8fe8-38cfba95a2cd.filesusr.com/ugd/70e7d4_b64eef06761d4675b88ae32fb58b775a.pdf?index=true
    • https://0c005061-34c5-455b-8ef0-e76b8fa017cc.filesusr.com/ugd/3f80ec_2dd5bc4a5f5049c78e41833b3c5272b9.pdf?index=true
    • https://ee4bb60c-ddc5-40f5-8ece-1892d4b9bb55.filesusr.com/ugd/fd4c29_671a14a98c3746f5a1d8cf97cc399a0b.pdf?index=true
    • https://2164f6d4-5266-4f3f-a89e-532e762ae8d0.filesusr.com/ugd/e3c460_4543dd82f94e40e3b5b0abe8c786f05b.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006642.bin
c46f1815d923f9dd8916f94a2a070e03ce0fa3c7de21a4f5a67b7e55f8ef767e
pdf-font-stream PDF embedded font (sfnt) at offset 0x6642 5156 bytes
font_01_sfnt_off00007803.bin
6b187f01b638d8db0d1ca26ce3e35bb09a7c1f57c8243bf6d8c90000ba6f6400
pdf-font-stream PDF embedded font (sfnt) at offset 0x7803 10528 bytes