Malicious PDF — malware analysis report

Static analysis result for SHA-256 91048e290811d3bc…

MALICIOUS

PDF

42.0 KB Created: 2020-09-01 19:53:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: afba8bf069a44fa2aa74237f5d6bf3e0 SHA-1: f5282a7c2940142a260a4d75fee920634c0aefa4 SHA-256: 91048e290811d3bc738868c8b2c16d24980f41f370dd03caae07b0cde1405a31
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains multiple embedded links, with one pointing to a known malicious redirector. The heuristic 'SE_ADVANCE_FEE_SCAM_LURE' indicates the document's content is designed to trick users into believing they have won a prize or are due a large sum of money, requiring them to interact with the provided links. The presence of a link farm further supports the malicious intent of directing users to potentially harmful sites.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=b%25C3%25B6hse+f%25C3%25BCrs+leben+dvd
    • https://static.usrfiles.com/ugd/aec2ea_26178cec568d4221983db054e8adc6fa.pdf
    • https://static.usrfiles.com/ugd/b8c837_5738208a719e47dabc1705be686f0a38.pdf
    • https://static.usrfiles.com/ugd/ed64d2_253ef0ee93284f969e2b2277f1fe647e.pdf
    • https://static.usrfiles.com/ugd/b8c837_24e161106c194280bc354221f0f6fc7c.pdf
    • https://static.usrfiles.com/ugd/9b33c5_dc26e4c91ddf4f50b14dec5b37de746b.pdf
    • https://static.usrfiles.com/ugd/d7ba0f_5ff4941105664d14b78c44c8551f7155.pdf
    • https://static.usrfiles.com/ugd/ee6770_a51576d04eeb42bdbf81e4aa8f199827.pdf
    • https://static.usrfiles.com/ugd/89064d_4859f553ab014a90be51a319cfeca1be.pdf
    • https://static.usrfiles.com/ugd/e3ff21_0fae3170e9334197ae0eab330b4d9766.pdf
    • https://cdn.shopify.com/s/files/1/0432/3088/8094/files/73713884322.pdf
    • https://cdn.shopify.com/s/files/1/0435/6302/4547/files/48201500285.pdf
    • https://static.usrfiles.com/ugd/05900a_86862a68d4bb434cbae4db163488e904.pdf
    • https://static.usrfiles.com/ugd/b8c837_392740da09dc486787b40294ec63f472.pdf
    • https://static.usrfiles.com/ugd/f80014_884aecb44eee47e3b68687b9b4fd018b.pdf
    • https://static.usrfiles.com/ugd/8b49c6_23eb849e0ec14deca78d16439b09ee51.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000063f5.bin
a91f10ff0f04b2f40ec0ef69aae796399f4b8bf8f94271989d0c0e008cbd603c
pdf-font-stream PDF embedded font (sfnt) at offset 0x63F5 5292 bytes
font_01_sfnt_off00007576.bin
1011847e0c1d316193a72dd65e601ccdbef0f17a0f1b8f2437ab397cd658c5fb
pdf-font-stream PDF embedded font (sfnt) at offset 0x7576 11008 bytes