Malicious PDF — malware analysis report

Static analysis result for SHA-256 84945140e827fe7d…

MALICIOUS

PDF

38.2 KB Created: 2020-07-14 22:33:30 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 570c9e8cc1172d345a0c4ee26c297318 SHA-1: 8602a83c3e0a9c44a8badef1a1c03872721bfbac SHA-256: 84945140e827fe7d42733f808b95d51a06951e4f32dcdb0d1308ba4e632d01bf
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for PDF_MALICIOUS_REDIRECTOR_LINK, indicating it directs users to malicious infrastructure. It also fires for PDF_SEO_LINK_FARM, suggesting a large number of outbound links. The primary malicious IOC is the redirector URL, which is likely used to host further malicious content or phishing pages. The document body, though heavily obfuscated, contains text related to grammar exercises, likely a lure.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wb?keyword=present%20simple%20tense%20and%20present%20continuous%20tense%20exercise%20pdf
    • http://files.reading2reading.com/uploads/1/3/0/9/130969555/49253ecafb.pdf
    • http://files.jeeperzoutpost.com/uploads/1/3/0/9/130968906/pukesimane_mumodonidu.pdf
    • http://files.animalecologylab.org/uploads/1/3/1/6/131607683/popategajuf_xanodexafavum.pdf
    • http://files.teacherbehn.com/uploads/1/3/0/7/130776081/jojewujabejepolipa.pdf
    • http://files.teacherbehn.com/uploads/1/3/0/7/130776081/jojewujabejepo
    • https://rafopez.files.wordpress.com/2020/06/98898466715.pdf
    • https://gudumik.files.wordpress.com/2020/06/jifezezimevokinakawidal.pdf
    • https://vusuletameta.files.wordpress.com/2020/07/jiwigupon.pdf
    • https://boruporo.files.wordpress.com/2020/07/lofokibivupafopitilafos.pdf
    • https://xofinositum.files.wordpress.com/2020/07/17866785950.pdf
    • https://suzoxafa.files.wordpress.com/2020/06/60140324264.pdf
    • https://cdn.shopify.com/s/files/1/0429/5986/3961/files/28229767844.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/571475918.pdf
    • https://cdn.shopify.com/s/files/1/0431/5630/8123/files/faxivutodowujed.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/rasamonuje.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/fikikotiv.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/woburorofinuxup.pdf
    • https://cdn.shopify.com/s/files/1/0430/7186/4993/files/rapobusetuzifeke.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000058dd.bin
3712b1a13086b712f77b95ef6c45e8056fbf9474fb84f548e2a50c6b518b059b
pdf-font-stream PDF embedded font (sfnt) at offset 0x58DD 5252 bytes
font_01_sfnt_off00006a90.bin
c5b7ee8352f205a8fde304131556a7caebbc3eacf879aaa19a622eda83c02b00
pdf-font-stream PDF embedded font (sfnt) at offset 0x6A90 9540 bytes