Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f72daf7505584d8…

MALICIOUS

PDF

33.3 KB Created: 2020-09-05 21:13:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6f7813903789f74d3bd1bde9e9b70ad4 SHA-1: 790f231f1077ecf86fff93b473fc74570ee6e2c5 SHA-256: 9f72daf7505584d83ae4e288f8332be7258a581fc55c3bf9e429887e7ea33327
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a link farm and a critical heuristic firing for a malicious redirector. The document body, though heavily obfuscated, contains the URL that triggered the malicious redirector heuristic. This suggests the document's primary purpose is to redirect users to malicious infrastructure, likely for further exploitation or phishing. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=dividing+decimals+with+negative+numbers+worksheet
    • https://cdn.shopify.com/s/files/1/0432/3993/2067/files/apotheosis_novel_download.pdf
    • https://cdn.shopify.com/s/files/1/0461/9721/1294/files/dopomovupipowadasipijafef.pdf
    • https://cdn.shopify.com/s/files/1/0433/7526/3909/files/getamubipafusunuxuwuf.pdf
    • https://cdn.shopify.com/s/files/1/0431/1790/4033/files/rojawoxegelakegedubeme.pdf
    • https://cdn.shopify.com/s/files/1/0431/0673/0144/files/22306766576.pdf
    • https://cdn.shopify.com/s/files/1/0428/2515/4716/files/libros_apocrifos_biblia.pdf
    • https://cdn.shopify.com/s/files/1/0437/3040/3477/files/seasons_and_ecliptic_simulator_worksheet.pdf
    • https://cdn.shopify.com/s/files/1/0434/1714/1415/files/javascript_game_codes.pdf
    • https://static.usrfiles.com/ugd/e4bc37_cf39d47c23134ad8be8cff6c2d81c50b.pdf
    • https://static.usrfiles.com/ugd/98857b_77eb2acfd6e947e59207655a7b4b9cfd.pdf
    • https://static.usrfiles.com/ugd/a44510_eb6ec3436c99428cac4e1ec538014fe1.pdf
    • https://static.usrfiles.com/ugd/50de67_b567ff6af9244a75b84b2c46b6602fc0.pdf
    • https://static.usrfiles.com/ugd/1e8759_c88af000db5b4960a41631706f66d3ee.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000439d.bin
263f7e456f06341d7b0e6ee88cbedc5f1549143dca9c0e569bce95e367a7f159
pdf-font-stream PDF embedded font (sfnt) at offset 0x439D 5708 bytes
font_01_sfnt_off000056ee.bin
f7336275e11b113ab3ccec182c6163ad753b7cae0a063ae58952cbfdfa8d3810
pdf-font-stream PDF embedded font (sfnt) at offset 0x56EE 9792 bytes