Malicious PDF — malware analysis report

Static analysis result for SHA-256 815276ddd2485818…

MALICIOUS

PDF

42.7 KB Created: 2020-08-15 12:27:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 55d835ad703bf947145b2f8e41d3c612 SHA-1: caa9e02a069a35a9b166f8eb5672a938d04920c8 SHA-256: 815276ddd248581834f67e11d3b10b3cea9aaee2bfbc22fed579a99f552b30fc
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a link farm designed to appear as legitimate PDF downloads, but the primary link redirects to known malicious infrastructure. The document body, though heavily obfuscated, contains the same lure text and the malicious URL. This indicates a social engineering attack aiming to redirect users to a malicious site.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wb?keyword=lineage%20of%20grace%20francine%20rivers%20pdf%20download
    • http://files.aspendivas.org/uploads/1/3/1/3/131384281/6365933.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/41718344304.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/60801944673.pdf
    • https://cdn.shopify.com/s/files/1/0432/4828/7904/files/pebavam.pdf
    • https://cdn.shopify.com/s/files/1/0430/4837/0333/files/fonezogorumekanitojego.pdf
    • https://cdn.shopify.com/s/files/1/0435/7141/3151/files/ravidinavanujosojibopam.pdf
    • https://cdn.shopify.com/s/files/1/0431/0918/7750/files/vaduvemagutifek.pdf
    • https://cdn.shopify.com/s/files/1/0433/6245/1611/files/zutina.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/54344474436.pdf
    • https://cdn.shopify.com/s/files/1/0439/3671/0824/files/giminugapeje.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000579c.bin
4267c0027083c89656efce0676b13e35b9b305c3713f1fb5d0bb9b509b0a3449
pdf-font-stream PDF embedded font (sfnt) at offset 0x579C 5416 bytes
font_01_sfnt_off00006a31.bin
b20b30e8a470a791091766356abd47a0dd004c16e4371cfc7fde44a82452400b
pdf-font-stream PDF embedded font (sfnt) at offset 0x6A31 15972 bytes