Malicious PDF — malware analysis report

Static analysis result for SHA-256 4018fb687e59b1c5…

MALICIOUS

PDF

43.8 KB Created: 2020-08-29 03:27:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3f9192290f71e93b41ab0232b458cd60 SHA-1: 7f79928c2156ebd164d75e2fc2852be5f25c8882 SHA-256: 4018fb687e59b1c50d9796b0d03c2af041666b60ce5b0b86bdebc2b220c3104e
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a significant number of embedded URLs, with one identified as a malicious redirector. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external links, suggesting an attempt to manipulate search engine results or distribute malicious content. The primary malicious URL identified is https://ttraff.cc/wix?keyword=escala+de+glasgow+actualizada+2019.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=escala+de+glasgow+actualizada+2019
    • https://static.usrfiles.com/ugd/b8c837_1f7374e4ddc74456af9432fd1a30e279.pdf
    • https://static.usrfiles.com/ugd/b8c837_3f1b2fc291d84aa599e22554a97cf840.pdf
    • https://static.usrfiles.com/ugd/b8c837_4bb78c9e5d064837b2103118abe422fc.pdf
    • https://cdn.shopify.com/s/files/1/0448/0483/3441/files/africa_country_and_capital.pdf
    • https://cdn.shopify.com/s/files/1/0431/0102/8503/files/91195393168.pdf
    • https://cdn.shopify.com/s/files/1/0433/4606/7621/files/92749661547.pdf
    • https://cdn.shopify.com/s/files/1/0431/6174/7620/files/sinonijujasewijokixiveju.pdf
    • https://cdn.shopify.com/s/files/1/0448/0519/3885/files/laundry_shop_business_plan.pdf
    • https://cdn.shopify.com/s/files/1/0434/3070/7356/files/aruba_clearpass_hardware_datasheet.pdf
    • https://cdn.shopify.com/s/files/1/0432/7692/7141/files/zefibifoxuxevuzib.pdf
    • https://cdn.shopify.com/s/files/1/0428/0510/0707/files/tulowaxakotudabogakuzojez.pdf
    • https://static.usrfiles.com/ugd/b8c837_3d4996c4c49c4289a8913bc5ffcd4555.pdf
    • https://static.usrfiles.com/ugd/b8c837_a4b6fcb9482148aca3017c43442dd105.pdf
    • https://static.usrfiles.com/ugd/b8c837_54eadc46311c449e81892e972544e22d.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000696b.bin
caf80cb1ade595d6d7ccc55910ed824144b69080c5dddaa566fb612e5245d0d5
pdf-font-stream PDF embedded font (sfnt) at offset 0x696B 5592 bytes
font_01_sfnt_off00007ca5.bin
d35919b7cc28ac39b06bd63e96c8b4f88b521c1f36bc43e79f75c5db885886b4
pdf-font-stream PDF embedded font (sfnt) at offset 0x7CA5 11084 bytes