Malicious PDF — malware analysis report

Static analysis result for SHA-256 37113442173d9034…

MALICIOUS

PDF

46.7 KB Created: 2020-08-30 13:20:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 70543aee2cd6b89ee79551c351c189a6 SHA-1: aa281676447a1a401f6aa113ef8e7c94717c1b2b SHA-256: 37113442173d9034f57b25f1da85e6367448edcb50397dd4458e101d278c6f26
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a link farm and a critical heuristic firing for a malicious redirector. The document body, though heavily obfuscated, contains text related to job applications and the primary malicious URL. This suggests a phishing attempt designed to lure victims through a seemingly legitimate theme and redirect them to malicious infrastructure.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=job+application+sample+in+pakistan+p
    • https://static.usrfiles.com/ugd/ab922d_d48466f6b7e14faea03ad9ba650e5056.pdf
    • https://static.usrfiles.com/ugd/55cc32_0bdec5886991418db6c1b03ae6470c60.pdf
    • https://static.usrfiles.com/ugd/b8c837_67e202df558441b9b48a5e8b9e5731da.pdf
    • https://static.usrfiles.com/ugd/f84671_7cf76ee3f59f4433993a9b57f9b76041.pdf
    • https://static.usrfiles.com/ugd/b8c837_456581d623724a0ba0fe5da1d497ffa4.pdf
    • https://static.usrfiles.com/ugd/dc98cc_520759641a514a5bbdd3e741a915c84e.pdf
    • https://static.usrfiles.com/ugd/b8c837_ad6db4e7bd4e4a28b890eaf435cc352e.pdf
    • https://static.usrfiles.com/ugd/764aaa_e12f37a899e0436b9abe37a13d5cc14f.pdf
    • https://static.usrfiles.com/ugd/b9801a_b91a85d9eca64ce7a180eaae26215a0c.pdf
    • https://static.usrfiles.com/ugd/8b2c09_18e78721391e426396d4a22bb8158dbb.pdf
    • https://static.usrfiles.com/ugd/b8c837_dc29d997332d4c2399494376c25d3128.pdf
    • https://static.usrfiles.com/ugd/2e4eb4_edb9ba7622f149cdbd6949051ed55fad.pdf
    • https://cdn.shopify.com/s/files/1/0434/9440/8354/files/27813236207.pdf
    • https://cdn.shopify.com/s/files/1/0430/4125/9671/files/13322946877.pdf
    • https://cdn.shopify.com/s/files/1/0429/6422/2101/files/73582334633.pdf
    • https://cdn.shopify.com/s/files/1/0435/2265/4362/files/doxizaxiwuvag.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000077f2.bin
482c17aa56387e3150cd13946dcca65fed826012d75ef81e0e4a1b74d11b02bb
pdf-font-stream PDF embedded font (sfnt) at offset 0x77F2 5176 bytes
font_01_sfnt_off00008977.bin
247441edf9c0b15af1206b92268df488ec859e9a4933d94a836e08b30ae5a7e8
pdf-font-stream PDF embedded font (sfnt) at offset 0x8977 10744 bytes