Malicious PDF — malware analysis report

Static analysis result for SHA-256 a837257123691871…

MALICIOUS

PDF

52.4 KB Created: 2020-08-29 12:28:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8d4e43f8b1fa3bdf4873bcc2fb9ac26b SHA-1: fe7d75ddc7be6f1acb37aaf955ee68d98e1fb32e SHA-256: a8372571236918716044e9a4634cc13bcb7a83ff07fd3a6019a68ce35aa2220c
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains multiple embedded links, with one critical heuristic identifying a link to a known malicious redirector. The document body, though heavily obfuscated, contains the same URL. This suggests the primary intent is to redirect the user to malicious infrastructure, likely for further exploitation or credential harvesting.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=paramahansa+yogananda+books+pdf+free
    • https://static.usrfiles.com/ugd/b8c837_049435b7521a46c4a353f38bb6e5166b.pdf
    • https://static.usrfiles.com/ugd/b8c837_1f22e99856ea4dbcb7403337c5073439.pdf
    • https://static.usrfiles.com/ugd/b8c837_8df3901255ba44f1b8b9395e60e75565.pdf
    • https://static.usrfiles.com/ugd/b8c837_6aae4917859e4932aac2d8b100caaea6.pdf
    • https://cdn.shopify.com/s/files/1/0429/5216/3482/files/1053992592.pdf
    • https://cdn.shopify.com/s/files/1/0435/7498/4863/files/kujofutigakatagog.pdf
    • https://cdn.shopify.com/s/files/1/0432/7129/1035/files/embryology_notes_for_medical_students_download.pdf
    • https://cdn.shopify.com/s/files/1/0462/7336/4130/files/anarchist_from_colony_sub_indo.pdf
    • https://cdn.shopify.com/s/files/1/0431/1983/7333/files/pufunoragu.pdf
    • https://cdn.shopify.com/s/files/1/0440/1142/1854/files/oxford_english_to_spanish_dictionary.pdf
    • https://cdn.shopify.com/s/files/1/0429/6730/2303/files/oracion_al_arcangel_san_miguel.pdf
    • https://cdn.shopify.com/s/files/1/0432/1509/3920/files/vaked.pdf
    • https://cdn.shopify.com/s/files/1/0431/5555/4470/files/kiwagexivuwujo.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://static.usrfiles.com/ugd/b8c837_8df3901255ba44f1b

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007f65.bin
ec92cc76c4694cfaf1f239d14007f431ebd9f5d43c670578e79cd53ec06de47b
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F65 4148 bytes
font_01_sfnt_off00008e00.bin
2ae194f83b46c287c3cfeb15c256f6a23091c4ffc8e3ede389aceaa0f404cf9d
pdf-font-stream PDF embedded font (sfnt) at offset 0x8E00 5732 bytes
font_02_sfnt_off0000a15d.bin
b19a9941a0f13c4d3f7410e169e1eb7663eb800f5516c2917a6653a5e3eb78a4
pdf-font-stream PDF embedded font (sfnt) at offset 0xA15D 10240 bytes