Malicious PDF — malware analysis report

Static analysis result for SHA-256 a707081b123affbc…

MALICIOUS

PDF

34.7 KB Created: 2020-09-19 22:18:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 50d27ac6a9d073d3ed31d366eb7b17db SHA-1: 077e1d38cc5b47a614767ba24c928dbc575581fa SHA-256: a707081b123affbcd93bf20a4c90dced2236edadd9ab72701a4a9e017705d5e5
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1200 Hardware Add-Override

The PDF file contains a heuristic firing for a malicious redirector link, which is also present in the document body. This link, 'https://ttraff.club/wix?keyword=fuquay+varina+lunch+restaurants', is designed to redirect users to potentially harmful content. The file also exhibits characteristics of a link farm, with numerous embedded URLs pointing to external PDF documents, suggesting an attempt to manipulate search engine results or distribute further malicious content. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=fuquay+varina+lunch+restaurants
    • http://xilil.panoramicshades.com/uploads/1/3/1/3/131398140/2974464.pdf
    • http://wumupi.mujournalismabroad.com/uploads/1/3/0/8/130813961/pafaligoxexi.pdf
    • http://files.newahecevents.org/uploads/1/3/0/8/130814078/187f9531640.pdf
    • http://files.clconroyartworks.com/uploads/1/3/1/6/131637695/betafetodu.pdf
    • https://441ce3ec-b7c6-4118-98d0-8cc91280b781.filesusr.com/ugd/54dfea_22dd1ac25bc24c03aaf3056e9372041d.pdf?index=true
    • https://8a4b342c-b766-4f34-a974-dfa0d3492df2.filesusr.com/ugd/7f929b_94167b6921d443acbbea6e9b71c525fa.pdf?index=true
    • https://cbbb2af7-fba8-4217-a751-c703f3d607eb.filesusr.com/ugd/26481d_5780972451a14740abe14f9fe2683447.pdf?index=true
    • https://d17d2687-1e63-467b-b157-052bff5dd928.filesusr.com/ugd/ca9b0a_73dc97fe1f5b449fbd16b95e80fd2aac.pdf?index=true
    • https://594c6192-4440-4f9b-bdf4-f8971b7c15c0.filesusr.com/ugd/3fc21f_30237c14b8e0468290c44b7abbc2e0de.pdf?index=true
    • https://0d1336da-83db-492b-9c18-ec4ce6dd9997.filesusr.com/ugd/e6092c_a62f5769de1449a99fb475ba0a1dd18a.pdf?index=true
    • https://98e67385-5358-4e0d-b3ab-3d67471f9f68.filesusr.com/ugd/bbd3cf_6808c1aa18d54ba9b3800db6c36b1b7b.pdf?index=true
    • https://0ecfb21b-e3a9-41ac-85fa-4afd566720b4.filesusr.com/ugd/b56239_2b3a13faaf2e47b393fc4b64893b5cff.pdf?index=true
    • https://06651b2b-1c8a-4831-b70b-8def4953a0e4.filesusr.com/ugd/73cb9e_bd0766e375de4cd3b32bffa1a8129039.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0437/7526/2869/files/balanza_de_pagos_colombia.pdf
    • https://cdn.shopify.com/s/files/1/0437/7447/6440/files/zukiliduwufu.pdf
    • https://cdn.shopify.com/s/files/1/0437/3918/5303/files/number_6_recycling_nyc.pdf
    • https://cdn.shopify.com/s/files/1/0486/4245/7758/files/kyocera_fs-1128mfp_service_manual.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004b50.bin
e0de09ae0a7901fd6af6f2bc0111f4b34a8e0a883dfda0455a9e067d0225283b
pdf-font-stream PDF embedded font (sfnt) at offset 0x4B50 5128 bytes
font_01_sfnt_off00005ccf.bin
29e74e426d13bb40de51bdabdbb6be0caa8e25caff3c1bfad0a79dc96917147d
pdf-font-stream PDF embedded font (sfnt) at offset 0x5CCF 9668 bytes