Malicious PDF — malware analysis report

Static analysis result for SHA-256 4366d34115ec1ffb…

MALICIOUS

PDF

67.7 KB Created: 2020-07-15 12:56:58 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6536352536cf4b29b9ad55eaba208dc6 SHA-1: 0f5f29f7e9678b3d15cbe557245a8e64c97f061c SHA-256: 4366d34115ec1ffb0c6ae4846ac551dc7c3a5b8db1a922372a0f5e65a21260f2
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1200 Hardware Add-in Systems T1059.001 PowerShell

The PDF file contains numerous embedded links, with one specifically identified as a malicious redirector. The document body, though heavily obfuscated, suggests a theme related to 'Hiperaldosteronismo secundário pdf'. The presence of a malicious redirector link indicates an attempt to direct users to harmful content, likely for phishing or malware distribution. The file was generated using wkhtmltopdf, which can be abused to create malicious PDFs.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wb?keyword=hiperaldosteronismo%20secund%C3%A1rio%20pdf
    • http://files.francishurley.com/uploads/1/3/1/3/131379181/9c50dd.pdf
    • http://files.dogologyct.com/uploads/1/3/1/3/131381640/nagasagazu.pdf
    • http://files.pchs.k12.il.us/uploads/1/3/2/6/132681343/8c3cbd89e2.pdf
    • https://dipenafuvepe538297139.files.wordpress.com/2020/07/kitawunurij.pdf
    • https://vomaxepe.files.wordpress.com/2020/07/kebuxozomowetisebibipidis.pdf
    • https://surugevebi358397781.files.wordpress.com/2020/07/todajilupofilupadi.pdf
    • https://zawisuvipid.files.wordpress.com/2020/06/zekebowopuxikutafisigumat.pdf
    • https://kitelineset.files.wordpress.com/2020/07/zosakowupot.pdf
    • https://janigamiviv.files.wordpress.com/2020/07/74617902189.pdf
    • https://jopawetudame.files.wordpress.com/2020/07/gibazogagimavotaz.pdf
    • https://kolojibujeji.files.wordpress.com/2020/07/60762284662.pdf
    • https://jepexifo574926731.files.wordpress.com/2020/07/nedadamulasumunugeterimeb.pdf
    • https://cdn.shopify.com/s/files/1/0431/1918/1985/files/xiwimaga.pdf
    • https://cdn.shopify.com/s/files/1/0428/3033/2060/files/gunelanimotenomuwovoloda.pdf
    • https://cdn.shopify.com/s/files/1/0432/5664/3739/files/lufosino.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/17612659915.pdf
    • https://cdn.shopify.com/s/files/1/0434/1940/2405/files/zilizuvegifu.pdf
    • https://cdn.shopify.com/s/files/1/0430/7963/1012/files/belulazadod.pdf
    • https://cdn.shopify.com/s/files/1/0432/8787/1646/files/kozebelesafukazirebix.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000bf4d.bin
651c762281b369c84822a20751b92220a3cee7dc2e54341aa2c8ee3b27c6f993
pdf-font-stream PDF embedded font (sfnt) at offset 0xBF4D 5376 bytes
font_01_sfnt_off0000d0e5.bin
e4eb58cb2c2cc3c7cb804eed4e856697428ec45888245d23a5861db45716cd2f
pdf-font-stream PDF embedded font (sfnt) at offset 0xD0E5 15408 bytes