Malicious PDF — malware analysis report

Static analysis result for SHA-256 9a84cb5f93a4a32d…

MALICIOUS

PDF

49.9 KB Created: 2020-07-10 16:29:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 40e532fcc6bdef2a51122b6d1fc257fa SHA-1: d53102b7bbb396148e9ceaef9cadbeb941d1519b SHA-256: 9a84cb5f93a4a32d49767008d0380bb30e8f3704da31f9e9c58b760926fa8593
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a mass external link farm, with many URLs pointing to seemingly generated PDF files. One of the primary links redirects to a known malicious infrastructure. The document body also contains the URL 'https://ttraff.cc/wb?keyword=pdf%20reader%20editor%20download', suggesting a lure to download a PDF reader, which is a common social engineering tactic.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wb?keyword=pdf%20reader%20editor%20download
    • http://files.anitamerrickauthor.com/uploads/1/3/0/9/130969048/bibigak-wujejobagiva-palabegu-lapujojeru.pdf
    • http://files.key2evolve.com/uploads/1/3/0/8/130874318/zasabuxemer_xawapikiguromik_balasoge.pdf
    • http://files.abeautifulmess.net/uploads/1/3/1/3/131383467/8000483.pdf
    • http://files.zanyunoodles.com/uploads/1/3/0/7/130739381/sikete-wemotuta.pdf
    • http://files.lisaannschraffasantin.com/uploads/1/3/1/1/131163910/vifofarerebe.pdf
    • http://files.catherineofsienaparish.org/uploads/1/3/1/3/131398597/3307851.pdf
    • http://files.nlg-pros.com/uploads/1/3/0/9/130969910/katixiratowapo.pdf
    • http://files.rentamark.net/uploads/1/3/1/4/131408942/zoruvoserezavu_fipubutumedi_basedu.pdf
    • http://files.sueannecelebrant.com/uploads/1/3/1/3/131379402/8511316.pdf
    • https://pezelid.files.wordpress.com/2020/06/53053927336.pdf
    • https://jafujanile.files.wordpress.com/2020/07/66108117721.pdf
    • https://bupotutozis.files.wordpress.com/2020/07/99075619313.pdf
    • https://datigexomup.files.wordpress.com/2020/06/90205495858.pdf
    • https://ditokixexup.files.wordpress.com/2020/07/38561144252.pdf
    • https://livevunomaz.files.wordpress.com/2020/06/febutodogir.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/juxupajajivamuwiri.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/setixinojed.pdf
    • https://cdn.shopify.com/s/files/1/0430/1550/4029/files/vikibozonorozu.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/rinavupomun.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/94323725826.pdf
    • https://cdn.shopify.com/s/files/1/0427/7387/2807/files/28906919120.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/16946396068.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000085e9.bin
767edec8d888ff0a71d2945da18c72d6924b675b0dc158b5f995b0051d50b249
pdf-font-stream PDF embedded font (sfnt) at offset 0x85E9 4604 bytes
font_01_sfnt_off0000959d.bin
794e679b9d44fd4207091c00c9a2f5553cd8555e230fc796ab6c08ec7b7f8eb2
pdf-font-stream PDF embedded font (sfnt) at offset 0x959D 10664 bytes