Malicious PDF — malware analysis report

Static analysis result for SHA-256 22dd0defabf06f47…

MALICIOUS

PDF

47.3 KB Created: 2020-09-01 17:28:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 678ddf630c93e5ddb91c9928c5b8ab74 SHA-1: 0148b4b79bd1bc5756490f99fba92dbf42105cbd SHA-256: 22dd0defabf06f4712d45f94568e8f8dd6c4eeb03ee94203c6f5b13748cba266
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a link that redirects to a malicious domain, identified by the PDF_MALICIOUS_REDIRECTOR_LINK heuristic. The document body, though heavily obfuscated, contains text related to 'Ean 128 barcode font free' and the malicious URL, suggesting a lure to download or access malicious content. The PDF_SEO_LINK_FARM heuristic indicates a large number of outbound links, many of which point to benign Shopify URLs, but the primary malicious redirector is the key indicator.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=ean+128+barcode+font+free
    • https://cdn.shopify.com/s/files/1/0428/0372/4455/files/zogetupu.pdf
    • https://cdn.shopify.com/s/files/1/0439/2887/9272/files/denila.pdf
    • https://cdn.shopify.com/s/files/1/0433/8185/0268/files/church_donation_letter.pdf
    • https://static.usrfiles.com/ugd/b8c837_c9cfdad9411f46a3af873fc3decc710c.pdf
    • https://static.usrfiles.com/ugd/dd4472_f489d7d7373846a48ec0a3a449068c76.pdf
    • https://static.usrfiles.com/ugd/b8c837_a9cc06c6fb374e959498cb5485af8591.pdf
    • https://static.usrfiles.com/ugd/e4f6f0_00dfec62206d4bcbb73ed8d989034054.pdf
    • https://static.usrfiles.com/ugd/b0b521_4ca8ebf0a7b749299c3a9d27155b628e.pdf
    • https://static.usrfiles.com/ugd/2ca09c_1cf0f67f2cea44c5960260c5ba32c19a.pdf
    • https://static.usrfiles.com/ugd/1cc777_b75e3928438e4af1bba31a5d4b495cfe.pdf
    • https://static.usrfiles.com/ugd/917232_1bddd721e88842afab9788390e180d43.pdf
    • https://static.usrfiles.com/ugd/b8c837_b458b3bc71f041ed8de160528ca3fe6f.pdf
    • https://static.usrfiles.com/ugd/dcfb95_3682460a528a47d8b397f0ca5e2b79c1.pdf
    • https://static.usrfiles.com/ugd/0049ca_8415985103dc4db9865bf5f86fdc8383.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005ed8.bin
f3b49ec9fd17392576ae06213b9df1b332ab26ba97b400e116ee609caabb4327
pdf-font-stream PDF embedded font (sfnt) at offset 0x5ED8 5280 bytes
font_01_sfnt_off000070e3.bin
c6811f2644a20087cc09db06ccfed2c5f44ce2486e6c511abad5adbff7043776
pdf-font-stream PDF embedded font (sfnt) at offset 0x70E3 10784 bytes
font_02_sfnt_off000095f3.bin
1f65fc381e04b81589e7a5b0ce00c66faea8c9aedccbbc7b2daa6c057c71a339
pdf-font-stream PDF embedded font (sfnt) at offset 0x95F3 17664 bytes