Malicious PDF — malware analysis report

Static analysis result for SHA-256 4cedbcff5bec43b4…

MALICIOUS

PDF

39.8 KB Created: 2020-08-07 16:10:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9679a0a553ff4d0387d1f2ca3b985e61 SHA-1: b9da376314f55441370da7b99e06794ab285d0cf SHA-256: 4cedbcff5bec43b4af82f93a37e16206a7f955cc79db723e2eea334a6fc0bbe8
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link farm designed to appear as free downloads, but the primary link redirects to known malicious infrastructure. The document body, though heavily obfuscated, contains the same lure text and the malicious URL. This indicates a social engineering attack aiming to redirect users to a malicious site.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wb?keyword=principles%20of%20management%20by%20tn%20chhabra%20pdf%20free%20download
    • http://files.livelearnsurvive.org/uploads/1/3/1/6/131637190/dd220df1b7.pdf
    • http://files.bakedbyalice.co.uk/uploads/1/3/0/7/130740012/gigevogoj.pdf
    • http://files.tidyfairyla.com/uploads/1/3/2/6/132681665/dd006.pdf
    • http://files.awardsdayton.com/uploads/1/3/2/7/132712373/7032474.pdf
    • https://cdn.shopify.com/s/files/1/0428/5726/7359/files/68179251289.pdf
    • https://cdn.shopify.com/s/files/1/0449/5890/8584/files/melissa_and_joey_season_1.pdf
    • https://cdn.shopify.com/s/files/1/0427/5326/1724/files/funoxirolemikojuzokipob.pdf
    • https://cdn.shopify.com/s/files/1/0434/1910/7480/files/26791487798.pdf
    • https://cdn.shopify.com/s/files/1/0437/0923/5353/files/99415167520.pdf
    • https://cdn.shopify.com/s/files/1/0438/5128/4642/files/tabasolofumuv.pdf
    • https://cdn.shopify.com/s/files/1/0430/4211/1650/files/49091229035.pdf
    • https://cdn.shopify.com/s/files/1/0433/3735/1323/files/xataxiredeboke.pdf
    • https://cdn.shopify.com/s/files/1/0431/9654/7230/files/77740219563.pdf
    • https://cdn.shopify.com/s/files/1/0434/3801/4616/files/algebra_textbook_of_10_std.pdf
    • https://cdn.shopify.com/s/files/1/0432/9265/5780/files/28823647978.pdf
    • https://cdn.shopify.com/s/files/1/0437/4337/9617/files/astm_a536_standard.pdf
    • https://cdn.shopify.com/s/files/1/0433/5586/5242/files/4162044296.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000046eb.bin
45e93f320cc0956864ff6290e10306b6f7bb5c4994fcff197686ac14e93703cb
pdf-font-stream PDF embedded font (sfnt) at offset 0x46EB 5904 bytes
font_01_sfnt_off00005ae3.bin
28ca19229b4d616c860f2c94037dee5fed24858987c411f18bf426d64114f8f3
pdf-font-stream PDF embedded font (sfnt) at offset 0x5AE3 9640 bytes
font_02_sfnt_off00007c43.bin
ebd2804bff382343e08f6a42dc45f69f4e794c08b23908ae60ba78ededae74b1
pdf-font-stream PDF embedded font (sfnt) at offset 0x7C43 16164 bytes