Malicious PDF — malware analysis report

Static analysis result for SHA-256 95a402d3e57ab5d2…

MALICIOUS

PDF

60.0 KB Created: 2020-09-01 01:42:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 83bbbd59db1a16c9a3ab4ded47b3932f SHA-1: 2ad32bfa8f5f53ec471b784f9cb63f71825ae264 SHA-256: 95a402d3e57ab5d2ff8bca5a74f2ee3751fdc516b49812a36f8b2b3067ea9faa
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a critical heuristic indicating it's a malicious redirector, linking to a URL that promises a 'bingo blitz hack tool free'. This URL is the primary IOC. The document body, though heavily obfuscated, also contains this URL, reinforcing the lure. The file's purpose is to redirect users to potentially malicious sites under the guise of offering a hack tool.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=bingo+blitz+hack+tool+free
    • https://static.usrfiles.com/ugd/e78b77_2e88e445d531411285ce532a42001611.pdf
    • https://static.usrfiles.com/ugd/f967ac_991cc56187074dfdbd2f8ade1a017c0a.pdf
    • https://static.usrfiles.com/ugd/26938b_5fea1e77bf9d42638b3108602045e387.pdf
    • https://static.usrfiles.com/ugd/0a0016_ef1984e5ad314e7893cc311f0216d4da.pdf
    • https://static.usrfiles.com/ugd/08fe48_524d9ed9213642ee92dea459649347b0.pdf
    • https://static.usrfiles.com/ugd/ea2f88_9f3fb6a9737043ffa257f66fe1278c5c.pdf
    • https://static.usrfiles.com/ugd/0511f5_8f3e7de503ad44368e81fa1d8870420c.pdf
    • https://static.usrfiles.com/ugd/b8c837_ffdba306e8c349b2bb3b062d0249fb7e.pdf
    • https://cdn.shopify.com/s/files/1/0435/5407/8883/files/brahmo_samaj_in_marathi.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/jisabisagubimebusogapasof.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/81274949660.pdf
    • https://cdn.shopify.com/s/files/1/0435/5253/8773/files/aiims_ka_full_form_kya_hota_hai.pdf
    • https://cdn.shopify.com/s/files/1/0436/4166/7734/files/school_attendance_register_format.pdf
    • https://cdn.shopify.com/s/files/1/0433/5032/7451/files/architectural_photography_techniques.pdf
    • https://cdn.shopify.com/s/files/1/0437/7939/1646/files/consecuencias_del_maltrato_psicologico_infantil_pdf.pdf
    • https://cdn.shopify.com/s/files/1/0428/0667/3575/files/52276515545.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009f1c.bin
8d4575b813f2b76f5eabca21a21ba0abde5ae3b22b983863bb6685abc72dbf42
pdf-font-stream PDF embedded font (sfnt) at offset 0x9F1C 5056 bytes
font_01_sfnt_off0000b044.bin
a2183d8e60750de8380d0646c4ce7bff0b589402dcbe5421e425a4b5a3cfaa90
pdf-font-stream PDF embedded font (sfnt) at offset 0xB044 11748 bytes
font_02_sfnt_off0000d4c6.bin
1062cd8ddf90f4344fa193b395386d5669df1a952e5759311ca261a71931f361
pdf-font-stream PDF embedded font (sfnt) at offset 0xD4C6 4324 bytes