Malicious PDF — malware analysis report

Static analysis result for SHA-256 598d19e265028311…

MALICIOUS

PDF

37.3 KB Created: 2020-08-31 11:59:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 50f9ac00abce49c9ce14269527d92948 SHA-1: 7ca33e49c92ef14e5a17506b4e2e88f127bf21de SHA-256: 598d19e265028311e58ba1fe60f36d96718088a64e060e5f2ffb337273f6fb56
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.001 Malicious Link

The PDF file contains a large number of embedded links, a common technique for SEO poisoning or redirecting users to malicious sites. One of the embedded URLs, 'https://ttraff.link/wix?keyword=m2n78-la+%2528violet6%2529+motherboard', is flagged as a known malicious redirector. The presence of a mass external PDF link farm further supports the malicious intent of this document.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=m2n78-la+%2528violet6%2529+motherboard
    • https://static.usrfiles.com/ugd/e6092c_f1b9edc4c471477186b046086b8b5ae5.pdf
    • https://static.usrfiles.com/ugd/696b8a_3a4a483862e143e9ab2834170af10909.pdf
    • https://static.usrfiles.com/ugd/fd7405_b68e712f9e154181917a8dbf41885fa5.pdf
    • https://cdn.shopify.com/s/files/1/0432/4248/7976/files/1202535472.pdf
    • https://cdn.shopify.com/s/files/1/0431/7842/6534/files/escape_from_tarkov_inventory.pdf
    • https://cdn.shopify.com/s/files/1/0433/6772/7269/files/10880264849.pdf
    • https://cdn.shopify.com/s/files/1/0430/4066/9849/files/19868746388.pdf
    • https://cdn.shopify.com/s/files/1/0433/4115/2406/files/aceptacion_radical.pdf
    • https://cdn.shopify.com/s/files/1/0428/9167/3763/files/34030036608.pdf
    • https://cdn.shopify.com/s/files/1/0435/1462/6202/files/kuxebewumu.pdf
    • https://cdn.shopify.com/s/files/1/0437/1657/5383/files/matter_and_measurement_uncertainty_worksheet_answers.pdf
    • https://cdn.shopify.com/s/files/1/0433/9856/1948/files/70542841533.pdf
    • https://cdn.shopify.com/s/files/1/0437/8374/9781/files/free_clock_face_template_with_minutes.pdf
    • https://cdn.shopify.com/s/files/1/0431/5453/8656/files/breakout_edu_platform_login.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000050ff.bin
3cd640cae8c61fedd810c096eb6ea6c605c360134e6217eefdec7fb613bb572d
pdf-font-stream PDF embedded font (sfnt) at offset 0x50FF 5836 bytes
font_01_sfnt_off000064cc.bin
9a371b75a1c30731fe4ba5ba7d6902a17c2210c28855331a92331006b3bc1721
pdf-font-stream PDF embedded font (sfnt) at offset 0x64CC 10428 bytes