Malicious PDF — malware analysis report

Static analysis result for SHA-256 3da761a300bff3b0…

MALICIOUS

PDF

38.5 KB Created: 2020-08-30 00:24:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 500d90b4819eb5cad04e56863445307f SHA-1: 065e2d01e2b95e7b94481c40f44f23449c8fdab2 SHA-256: 3da761a300bff3b024494b86dc6f9727fb73832bea04669e2a7d0f58d900a52e
128 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious Link T1566.002 Spearphishing Attachment

The PDF file contains a mass external link farm, with a critical heuristic firing for a malicious redirector link. The document body, though heavily obfuscated, contains text related to 'Farmville 2 expansion cheat 2017' and includes the malicious URL. The presence of a visual download button lure further supports the malicious intent. The primary IOC is the redirector URL which is likely used to host or chain to further malicious content.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=farmville+2+expansion+cheat+2017
    • https://cdn.shopify.com/s/files/1/0430/3178/9721/files/despacito_piano_notes.pdf
    • https://cdn.shopify.com/s/files/1/0430/5957/6986/files/waveguide_dispersion_in_optical_fiber_ppt.pdf
    • https://cdn.shopify.com/s/files/1/0440/7685/9544/files/zusafipoz.pdf
    • https://static.usrfiles.com/ugd/b58d21_0a0c94ee7fd346b8bdf25e8b9c9a8ceb.pdf
    • https://static.usrfiles.com/ugd/b8c837_1bf73c9469a149e29844297101e16ec4.pdf
    • https://static.usrfiles.com/ugd/b8c837_6bdce39293c54a7a9f3752d5b4024c03.pdf
    • https://static.usrfiles.com/ugd/b8c837_8647b3c843e949dc9afb1a4109e3314e.pdf
    • https://cdn.shopify.com/s/files/1/0437/7287/0807/files/tajoma.pdf
    • https://cdn.shopify.com/s/files/1/0431/1888/7068/files/walmart_employee_handbook.pdf
    • https://cdn.shopify.com/s/files/1/0433/5288/3352/files/xawomanison.pdf
    • https://cdn.shopify.com/s/files/1/0447/8281/3341/files/nepali_calendar_2020.pdf
    • https://cdn.shopify.com/s/files/1/0438/5194/0000/files/blueberry_pie_nutrition_information.pdf
    • https://static.usrfiles.com/ugd/b8c837_57681999b6bc4d45b4d83e7b1130e6ef.pdf
    • https://static.usrfiles.com/ugd/b8c837_d11437a55e144f4ba2404a42807a9aa8.pdf
    • https://static.usrfiles.com/ugd/4b874d_26370084682c4f3593f150ee82ccb5a8.pdf
    • https://static.usrfiles.com/ugd/12dc78_7cec4618ed0f451390bae2db25409253.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000057b9.bin
d1fcb3f9c666218f36d3a5bf543cfd4e37eb753f783332649dd0dfd52faea477
pdf-font-stream PDF embedded font (sfnt) at offset 0x57B9 5664 bytes
font_01_sfnt_off00006ae0.bin
a9258826b283097710b784da24f907299951d960b566dd9aae31defec5897f74
pdf-font-stream PDF embedded font (sfnt) at offset 0x6AE0 10124 bytes