Malicious PDF — malware analysis report

Static analysis result for SHA-256 88093bdb997a759d…

MALICIOUS

PDF

44.6 KB Created: 2020-09-10 09:46:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 55dd6357188d63e62490289f146ee6cd SHA-1: a603702b9ca8bb4e8c67a18960fbee2bb005c096 SHA-256: 88093bdb997a759d7d848be38d4d0047cc2a9d33bdbd446957b15fcc558119e5
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1200 Hardware Add-in

The PDF file contains a large number of embedded links, many of which point to a redirector service. The primary heuristic firing indicates that the PDF links to known malicious redirector infrastructure. The document body, though heavily obfuscated, contains the URL https://ttraff.club/pify?keyword=various+sustainability+reporting+framework, which is flagged as malicious. This suggests the document is designed to redirect users to malicious content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/pify?keyword=various+sustainability+reporting+framework
    • http://files.uniquebyruth.com/uploads/1/3/1/4/131483009/zigatakajumi.pdf
    • http://files.dopekonect.net/uploads/1/3/1/4/131438538/davexabodezugi.pdf
    • http://files.rbmt.org/uploads/1/3/1/4/131437891/6722de6a64bc633.pdf
    • http://xagoreto.coffeejustgothealthier.com/uploads/1/3/1/3/131381886/e8a12e.pdf
    • http://ruwida.lovelocalnashville.com/uploads/1/3/1/4/131408027/2334972.pdf
    • https://static.usrfiles.com/ugd/4c76bf_d01b205c4e724adeae7a7babcf5f31eb.pdf
    • https://static.usrfiles.com/ugd/c5d40f_2e1d0d19268d4cf3b158e61b9514c41e.pdf
    • https://static.usrfiles.com/ugd/b8c837_7f825cf65625495496c79e78b526030c.pdf
    • https://static.usrfiles.com/ugd/bfbc46_2b9e35c6e9294455bed2dd818f45ecaa.pdf
    • https://static.usrfiles.com/ugd/77941b_4ad3b41539094ab2a9b5164f15068f24.pdf
    • https://static.usrfiles.com/ugd/de9003_b5eb978439114d0296b676cb4ea46f4f.pdf
    • https://static.usrfiles.com/ugd/e02969_ecbeb8cf78ad4530a8470740dd87b3bb.pdf
    • https://static.usrfiles.com/ugd/e4a001_ce8b840a29dc4777be7c88af4ec65a16.pdf
    • https://static.usrfiles.com/ugd/041b56_a1765857d1af49128677f5e902e7693b.pdf
    • https://static.usrfiles.com/ugd/268ab1_822c1c36d89040328fa5eb4ccf7353e3.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006206.bin
4eaadcf4efa371aac4c9e878630b68392bbc61acc4294d81a5458212bb0a119e
pdf-font-stream PDF embedded font (sfnt) at offset 0x6206 5464 bytes
font_01_sfnt_off000074aa.bin
b1f9758060afd6eafddd30e432211aa71511f2d56abc821ef3b5d53329678a5e
pdf-font-stream PDF embedded font (sfnt) at offset 0x74AA 10088 bytes
font_02_sfnt_off0000972a.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0x972A 4324 bytes