Malicious PDF — malware analysis report

Static analysis result for SHA-256 87cba282526322a0…

MALICIOUS

PDF

37.5 KB Created: 2020-08-30 04:40:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3e32077a220c6b7925c54c4d5dc49491 SHA-1: 20a167ed6366e614b63e3f387d744b081e9b889e SHA-256: 87cba282526322a017d168a7211b67351ebd894e66b605ec554ab15a1e8b3bb4
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a lure related to 'church musician salary guidelines' and embeds a link to a known malicious redirector. The heuristic firings indicate that the PDF is designed to redirect users to malicious infrastructure and functions as a link farm. Although no scripts were extracted, the presence of a malicious link and the invoice lure suggest a phishing or scam attempt.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=church+musician+salary+guidelines
    • https://static.usrfiles.com/ugd/362633_3ff813c0b252400183496bf0feb7a328.pdf
    • https://static.usrfiles.com/ugd/0f5b72_eb8372bf02784c8290586443b63ce024.pdf
    • https://static.usrfiles.com/ugd/ae059d_e2471b44c66e43d29df2c8f3a2be577e.pdf
    • https://static.usrfiles.com/ugd/b8c837_ff00c782878243f186a064583f7b7c58.pdf
    • https://static.usrfiles.com/ugd/3b47cb_e458b032f7fc4da98475db9b27c4c84c.pdf
    • https://static.usrfiles.com/ugd/e42ee3_f603c4102e83416691ff569b984ac8dd.pdf
    • https://static.usrfiles.com/ugd/e8506d_337e180f05fc4991ab6812d3f7d4ba0a.pdf
    • https://static.usrfiles.com/ugd/cac9e4_c2c6f3465a424f6391b5b1719b5ac938.pdf
    • https://static.usrfiles.com/ugd/6a7407_72a1d9a6f27f4a26927e2a4e288b7b0e.pdf
    • https://static.usrfiles.com/ugd/b8c837_c70d88f7119f4663adb1b4f88511552c.pdf
    • https://static.usrfiles.com/ugd/b77b08_3af588110aab4c2aa3f737f7c80e7c6b.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000053eb.bin
0820f004ef8f5ca9cb2e4ebdccedacdb822539afa67c9bd9b2b5ded3fd6a8601
pdf-font-stream PDF embedded font (sfnt) at offset 0x53EB 5360 bytes
font_01_sfnt_off000065f9.bin
681be71f08b63c215174f10c53811a105603d0b57e3c16b2b314d9d971373b66
pdf-font-stream PDF embedded font (sfnt) at offset 0x65F9 10432 bytes