Malicious PDF — malware analysis report

Static analysis result for SHA-256 7b3401f515bb34a0…

MALICIOUS

PDF

36.9 KB Created: 2020-07-09 18:29:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8dd88d84f8281bbbb430f30a0d180136 SHA-1: 56cf131fc1470c078eeaeaae59de1a261d659fb6 SHA-256: 7b3401f515bb34a0883c1377ad7c03c16b7b94d94aae6d7c99b908e4e18cbb01
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document exhibits a link farm pattern, with numerous embedded URLs pointing to external resources. One critical heuristic identified a link to known malicious redirector infrastructure, suggesting a phishing or malware distribution attempt. The document body, though partially corrupted, contains text related to a 'farm animal baby matching worksheet' and the authoring tool 'wkhtmltopdf', which is often used to generate malicious PDFs. The primary attack pattern involves leveraging these links to lure users to potentially harmful sites.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wb?keyword=farm%20animal%20baby%20matching%20worksheet
    • http://files.fablegroundscoffee.com/uploads/1/3/1/8/131856071/rezages-nujaja-xinavena-nimofo.pdf
    • http://files.memortazavi.com/uploads/1/3/1/0/131070389/a5b2ace.pdf
    • http://files.danberkey.net/uploads/1/3/1/4/131453823/jolego_memux_puzalemozotil.pdf
    • http://files.paulsfranchiseleague.com/uploads/1/3/1/4/131438249/kabuvoxije_kuvorenuzixuw_raxejusub.pdf
    • http://files.corunnatrack.com/uploads/1/3/1/3/131378921/803d2fad.pdf
    • http://files.arlingtonmsband.com/uploads/1/3/1/6/131606087/ddee7.pdf
    • http://files.nurturedbirthservices.com/uploads/1/3/0/8/130813646/6143167.pdf
    • http://files.haralsoncountyhistory.com/uploads/1/3/2/3/132302913/4438840.pdf
    • http://files.townofhartlepool.com/uploads/1/3/1/6/131606673/4121719.pdf
    • http://files.authorrebeccaarogers.com/uploads/1/3/1/6/131637034/wakobobo_jujorufaxeso_puxul.pdf
    • http://files.rdfsports.co.uk/uploads/1/3/1/1/131163561/faf924c.pdf
    • http://files.azkillerbeessoftball.com/uploads/1/3/0/8/130874518/jemizip.pdf
    • https://karutetok765055257.files.wordpress.com/2020/07/63518816382.pdf
    • https://wosevapog526532590.files.wordpress.com/2020/07/tukovubizobope.pdf
    • https://kuperira.files.wordpress.com/2020/07/803842752.pdf
    • https://vopexuzufu.files.wordpress.com/2020/07/depofefizo.pdf
    • https://zixesope.files.wordpress.com/2020/07/10287599707.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/39843759369.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/bizisumexu.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/74523611049.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/70745323757.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000534a.bin
c5e41000c8a204ee4a031f0227805498bd114640a72512fe62525a3f1ba35f15
pdf-font-stream PDF embedded font (sfnt) at offset 0x534A 5356 bytes
font_01_sfnt_off0000655d.bin
a37769292e4b5b8409e33790254f8efe8c6b1f6692485673575dd28faf5f8c71
pdf-font-stream PDF embedded font (sfnt) at offset 0x655D 9740 bytes