Malicious PDF — malware analysis report

Static analysis result for SHA-256 228aa2204c4d9d6b…

MALICIOUS

PDF

56.5 KB Created: 2020-09-07 09:39:54 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3bfd8d047e1f87b21fcc8a6e8916b542 SHA-1: 867e1b902b4636231d43bffef62991bcca83590b SHA-256: 228aa2204c4d9d6b5e383db9e8f0d5550538032e74c858727a70683109ca2263
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a link farm and a critical heuristic firing for a malicious redirector. The document body, though heavily obfuscated, contains the text "Image file formats worksheet answers" and a URL that matches the malicious redirector. This suggests the document is designed to trick users into clicking the malicious link, likely leading to further malware download or phishing. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=image+file+formats+worksheet+answers
    • https://cdn.shopify.com/s/files/1/0435/8009/6667/files/stop_windows_update.pdf
    • https://cdn.shopify.com/s/files/1/0427/7737/8972/files/603368744.pdf
    • https://cdn.shopify.com/s/files/1/0431/7839/3762/files/loniru.pdf
    • https://cdn.shopify.com/s/files/1/0430/0469/0581/files/26745227867.pdf
    • https://cdn.shopify.com/s/files/1/0434/5597/1480/files/powanapaluneni.pdf
    • https://cdn.shopify.com/s/files/1/0433/4272/5275/files/faringitis_aguda_bacteriana.pdf
    • https://cdn.shopify.com/s/files/1/0433/4374/1083/files/supersport_5_tv_guide_tomorrow.pdf
    • https://cdn.shopify.com/s/files/1/0429/8362/0757/files/fogaxusowizek.pdf
    • https://cdn.shopify.com/s/files/1/0430/0223/2983/files/foluxujegesej.pdf
    • https://cdn.shopify.com/s/files/1/0427/9762/9596/files/merudadezomobomado.pdf
    • https://cdn.shopify.com/s/files/1/0433/3957/9546/files/congruent_triangles_word_search_answers.pdf
    • https://cdn.shopify.com/s/files/1/0433/7850/7934/files/57242800504.pdf
    • https://static.usrfiles.com/ugd/e1d58f_27891b203468451dab589078466f10b9.pdf
    • https://static.usrfiles.com/ugd/2d797c_dcd97516f75c43238c609df2bc647ae4.pdf
    • https://static.usrfiles.com/ugd/2f3ac6_172faff1b4b54e13932a1cf9e56e33c0.pdf
    • https://static.usrfiles.com/ugd/c4ccc4_c4aa0155c6a1474f8a37d23aaf89f951.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007c08.bin
970ea615b9b20eb635d98c6ebcbacf4aad61c4e26ca24239273459f9fbebe4a5
pdf-font-stream PDF embedded font (sfnt) at offset 0x7C08 5064 bytes
font_01_sfnt_off00008d20.bin
fd31f7daaced79b5f2f2cd58a03e42d08da58b8247d23a9bb7dd85e714e6ff12
pdf-font-stream PDF embedded font (sfnt) at offset 0x8D20 10368 bytes
font_02_sfnt_off0000b0c1.bin
0c82561ead172ac0e51412abe629b5944d5f81f469066018c017fef234fe4ba7
pdf-font-stream PDF embedded font (sfnt) at offset 0xB0C1 16388 bytes
font_03_sfnt_off0000c64d.bin
a542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f
pdf-font-stream PDF embedded font (sfnt) at offset 0xC64D 4324 bytes