Malicious PDF — malware analysis report

Static analysis result for SHA-256 55db29a6801030fc…

MALICIOUS

PDF

48.2 KB Created: 2020-10-07 21:40:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 416dab6eac4e61e89ba375078c1e1836 SHA-1: 50820af08e9da44a4f719ffc0c1ac540dbb82ccc SHA-256: 55db29a6801030fca0a8051b5bf468d64692a476f1c63c4eb89afde5e535db5f
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a link to a known malicious redirector, 'gettraff.ru', which is presented to the user under the guise of information about 'black swallow wort'. The file also contains a large number of links to other PDF files hosted on various domains, suggesting a link farm or SEO poisoning tactic. No scripts were extracted from this sample, and the document body was heavily obfuscated, making it difficult to determine the exact payload or further stages.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://gettraff.ru/pify?keyword=black+swallow+wort+how+to+get+rid+of
    • http://files.irishsetter.is/uploads/1/3/0/7/130739059/5001898.pdf
    • http://files.niebna.org/uploads/1/3/0/8/130813837/xisixoganiwe.pdf
    • http://files.angellight.lt/uploads/1/3/1/4/131438150/sojedanupu.pdf
    • http://files.georgesweeneyarchitect.com/uploads/1/3/0/7/130739719/8363314.pdf
    • http://files.doaprowrestling.com/uploads/1/3/1/6/131606111/definunipumus-seketomawom.pdf
    • http://files.renndrive.com/uploads/1/3/1/1/131163494/4045963.pdf
    • http://files.sandsfoleyentertainment.com/uploads/1/3/1/1/131164460/04f9fbecd6d3b39.pdf
    • http://files.drheatherloenser.com/uploads/1/3/1/8/131858916/4677354.pdf
    • http://zinivix.writepathint.com/uploads/1/3/1/8/131856033/vimulutidaj_jivufif.pdf
    • http://files.lifealignedrolfing.com/uploads/1/3/2/3/132302978/xifegozeme.pdf
    • https://cdn.shopify.com/s/files/1/0428/8364/5599/files/wimbledon_live_streaming_free_channel_7.pdf
    • https://cdn.shopify.com/s/files/1/0483/7746/2937/files/bugbear_clan_names.pdf
    • https://cdn.shopify.com/s/files/1/0434/7301/0845/files/29857369759.pdf
    • https://cdn.shopify.com/s/files/1/0434/7301/0850/files/sosikapewikin.pdf
    • https://cdn.shopify.com/s/files/1/0479/7992/1564/files/national_corn_growers_association_photo_contest.pdf
    • https://uploads.strikinglycdn.com/files/e2d9b55b-eb51-4fa5-8fd7-675c53f0626f/96587113394.pdf
    • https://uploads.strikinglycdn.com/files/4966c6dc-955c-4c3d-9d55-a414a8e3dbc7/niwowupozivuwa.pdf
    • https://uploads.strikinglycdn.com/files/7c5610f3-b063-4fdb-add7-6f09719f862a/84413016539.pdf
    • https://uploads.strikinglycdn.com/files/1dc7dd5e-7c85-4dd9-8313-bc332d02ea34/52178380624.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007dd4.bin
64087e84cc76291710a575e63867deaf05265e08a02de964b461c1e6739ddd06
pdf-font-stream PDF embedded font (sfnt) at offset 0x7DD4 5488 bytes
font_01_sfnt_off00009091.bin
fe9b8a4c46b970b8d4b68ec0583de1e898d7ef706f5b1a5b66d495dc44dee6bf
pdf-font-stream PDF embedded font (sfnt) at offset 0x9091 10192 bytes