Malicious PDF — malware analysis report

Static analysis result for SHA-256 7f4e8df75d40d533…

MALICIOUS

PDF

47.5 KB Created: 2020-09-21 04:49:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7ca869f46ebcf1f19282334737175682 SHA-1: 70b42e982bfa791a6a0cd791e625da5bdc5c3abe SHA-256: 7f4e8df75d40d53331e12e90ee600fe83ca7bd8db023247ffb53c75288fd3683
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a critical heuristic firing for a malicious redirector link, specifically pointing to a URL that appears to be a lure for 'chapter 13 chemistry answers'. This URL, along with numerous other PDF links embedded within the document, suggests a link farm or redirection scheme. The document body, though heavily obfuscated, contains the same suspicious URL and text, reinforcing the lure. The primary intent appears to be redirecting users to malicious infrastructure under the guise of providing educational material.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=chapter+13+chemistry+answers
    • http://files.chairssite.com/uploads/1/3/1/4/131406849/debawomuwi_xireruxuv_zalidadisuzex.pdf
    • http://files.offthegrid24.com/uploads/1/3/0/7/130739718/fefapi.pdf
    • http://files.beautifuldefect.com/uploads/1/3/1/1/131163872/ruvuradopadol-pedamaxud.pdf
    • http://jegoj.humanitiesladder.org/uploads/1/3/1/6/131606197/06d04885.pdf
    • http://perir.virtualracesusa.com/uploads/1/3/0/8/130814328/gizureburibogat-pugigazarako-diwokov-detawomarezo.pdf
    • https://e0e900c1-bc2c-4389-8026-c416c660bad3.filesusr.com/ugd/a2d007_e0d01654ef6d4b719fb4e4e325d7762c.pdf?index=true
    • https://d58e746e-8bf2-4348-9b29-8006837f3a6a.filesusr.com/ugd/0182ef_6c6f8465d7d447bfa7f5f6c8b92b2d0e.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/kupenase.pdf
    • https://cdn.shopify.com/s/files/1/0428/8924/8924/files/assetto_corsa_drift_setup_guide.pdf
    • https://cdn.shopify.com/s/files/1/0438/5662/5829/files/zolumafenamiwegit.pdf
    • https://cdn.shopify.com/s/files/1/0433/1310/2998/files/52933450580.pdf
    • https://a9f07397-fe83-4b8c-9ec7-79bfdc60583b.filesusr.com/ugd/4479ed_e00c17287054485da316a2ceab533dec.pdf?index=true
    • https://b36891e6-69a7-4841-a3c3-13088212e1af.filesusr.com/ugd/9ec29b_f6bbe0261ed445c0a291a8973b316c9a.pdf?index=true
    • https://86f86c7b-8de2-4d5a-8da0-1ed6d2832a32.filesusr.com/ugd/cc089a_3ffc165d590f4ca99c951a2809777fd6.pdf?index=true
    • https://535fa157-4dd5-498a-967a-4c5de41300b4.filesusr.com/ugd/112488_ca7b1992b8594ec9bb0043bc53240265.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007b1a.bin
1e35f7ba74fc185e23a61414d2b0a4e93a5b0b8188039e15cae26810ef12df8c
pdf-font-stream PDF embedded font (sfnt) at offset 0x7B1A 5456 bytes
font_01_sfnt_off00008d96.bin
1b4cb605b827400eb5b53ad5f99f674cdaa90e5d308aeabd7369c9d0865944b9
pdf-font-stream PDF embedded font (sfnt) at offset 0x8D96 10516 bytes