Malicious PDF — malware analysis report

Static analysis result for SHA-256 7f1a47266329f7b3…

MALICIOUS

PDF

42.6 KB Created: 2020-08-29 05:45:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 915cf98ef738f807559ca5a7f01010d4 SHA-1: 179a93617cb4cdee985f7e34d228fa9f6c9f5745 SHA-256: 7f1a47266329f7b34813abece482307d0ddb41341bd2fbb71f1a722ffb9783ec
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, many of which point to a redirector service. The document body text, though corrupted, appears to be a lure for a game ROM download, which is a common tactic for distributing malware. The primary malicious IOC is the redirector URL, which likely leads to further malicious content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=pokemon+adventure+red+chapter+beta+14.5+gba+rom+download
    • https://static.usrfiles.com/ugd/b8c837_e75a7c651e56461a906c270a2755499c.pdf
    • https://static.usrfiles.com/ugd/b8c837_b0a6355140284d5ea78165582bcba1ee.pdf
    • https://static.usrfiles.com/ugd/b8c837_5f19310028e14f2b8cd2f16550b27979.pdf
    • https://static.usrfiles.com/ugd/b8c837_3cc6f02fb8b14d88ac3c5a7bb30b2a08.pdf
    • https://static.usrfiles.com/ugd/b8c837_ac23a4f772fe4f60a5c85883bd59d198.pdf
    • https://static.usrfiles.com/ugd/b8c837_0f4337d527b0459bb485e190405982be.pdf
    • https://static.usrfiles.com/ugd/b8c837_d2401dbab147461d859b36180dd7b474.pdf
    • https://static.usrfiles.com/ugd/b8c837_4b325034c3ac43358f92acff711f3c58.pdf
    • https://cdn.shopify.com/s/files/1/0438/5108/8032/files/chrono_trigger_endings.pdf
    • https://cdn.shopify.com/s/files/1/0435/4975/3507/files/lirazigixawurawemekasiwo.pdf
    • https://cdn.shopify.com/s/files/1/0451/0213/7496/files/barriers_to_entry_in_an_industry.pdf
    • https://cdn.shopify.com/s/files/1/0440/0631/0046/files/61806690540.pdf
    • https://static.usrfiles.com/ugd/b8c837_acc9de464a35427b99cb71e95afca048.pdf
    • https://static.usrfiles.com/ugd/b8c837_05d5040985d642f49455785083da860d.pdf
    • https://static.usrfiles.com/ugd/b8c837_d63e9179ec9c4057915a8716084d9ae0.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000064ef.bin
d71003eed8d9d918f5962011806d51b79766e8f383d881b098357665ad03a40b
pdf-font-stream PDF embedded font (sfnt) at offset 0x64EF 5960 bytes
font_01_sfnt_off0000792c.bin
7141ca8bf2d0a670c6c8a2ca4070911a21089c4928b5dcf63c66b1a11d8264b1
pdf-font-stream PDF embedded font (sfnt) at offset 0x792C 10568 bytes