Malicious PDF — malware analysis report

Static analysis result for SHA-256 7aff9deeff7fdfbd…

MALICIOUS

PDF

74.0 KB Created: 2020-07-19 20:58:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 70f30b645c8080b960011d6b3057c8a7 SHA-1: cc58412389b6102837fd2f13271ad5fceb385bbb SHA-256: 7aff9deeff7fdfbdfd60665de7c32b1fb2f59598b0e2955782e9709a8ad42f2b
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, many of which point to domains that appear to be part of a link farm designed for SEO manipulation. One critical heuristic identified a link to a known malicious redirector. The document body, though heavily obfuscated, contains text related to 'cause and effect of water pollution essay pdf', suggesting a lure to trick users into clicking malicious links disguised as academic content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wb?keyword=cause%20and%20effect%20of%20water%20pollution%20essay%20pdf
    • http://files.danamsd.com/uploads/1/3/2/6/132695493/24e7ff960e.pdf
    • http://files.flawlessreflectionsautodetailing.com/uploads/1/3/1/4/131437756/4025e4268.pdf
    • http://files.alabasterliving.com/uploads/1/3/0/7/130775372/7445875.pdf
    • http://files.icanisciolti.com/uploads/1/3/2/6/132695372/panowawuxu-kiwek-wetizawi.pdf
    • http://files.imageupphotography.com/uploads/1/3/0/8/130873997/6439146.pdf
    • http://files.psycholoog-gooi.net/uploads/1/3/0/7/130738719/suwerulotopu.pdf
    • http://files.shelleygentry.com/uploads/1/3/0/9/130969428/rikegopege_punaxugozaz_temivivep.pdf
    • http://files.hawkfieldpointers.com/uploads/1/3/1/1/131164418/musijutowapun_vomoka.pdf
    • http://files.liquidsunshinedesigns.net/uploads/1/3/1/6/131606644/6427307.pdf
    • http://files.shelleygentry.com/uploads/1/3/0/9/130969428/rikegopege_punaxugozaz_temivivep
    • https://gozikes.files.wordpress.com/2020/07/74562535358.pdf
    • https://tigimizi.files.wordpress.com/2020/07/gupasud.pdf
    • https://topinideteba.files.wordpress.com/2020/07/4155404997.pdf
    • https://cdn.shopify.com/s/files/1/0430/3034/7938/files/sirajumagapifiginazo.pdf
    • https://cdn.shopify.com/s/files/1/0432/3944/0543/files/juvubufufomavanom.pdf
    • https://cdn.shopify.com/s/files/1/0432/9373/7110/files/dobulezinubixewomewine.pdf
    • https://cdn.shopify.com/s/files/1/0431/1311/9905/files/46166698651.pdf
    • https://cdn.shopify.com/s/files/1/0431/3530/3831/files/ledebowekatebuvofus.pdf
    • https://cdn.shopify.com/s/files/1/0430/9073/9361/files/gabidolobikekufinanotig.pdf
    • https://cdn.shopify.com/s/files/1/0429/6487/7471/files/desipimiwusixo.pdf
    • https://cdn.shopify.com/s/files/1/0430/2651/4077/files/44729255268.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e3de.bin
c9bd2395e6ba51c5407a5f87da36a62c4540893a3f52d8bf67c4ad5b59acef27
pdf-font-stream PDF embedded font (sfnt) at offset 0xE3DE 5248 bytes
font_01_sfnt_off0000f5de.bin
78b1b9c6cd13d176feafe5995e884cde9ce4a8e34c9cb451e6c2364035b9dd6a
pdf-font-stream PDF embedded font (sfnt) at offset 0xF5DE 10564 bytes