Malicious PDF — malware analysis report

Static analysis result for SHA-256 aa9e0c9a25888c73…

MALICIOUS

PDF

45.3 KB Created: 2020-09-01 06:14:52 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3e29ccf29133e73dae1dbb7d5350e72d SHA-1: 2af3799d6782d0da05e4c5413dfcd4f71b33770e SHA-256: aa9e0c9a25888c73bd506265b654c7b46e41644dddaf6f4f169b7f374834bade
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a link that redirects to a known malicious domain, identified by the PDF_MALICIOUS_REDIRECTOR_LINK heuristic. The document body, though partially corrupted, contains text related to a video game guide, likely serving as a lure. The PDF also contains a large number of external links, as flagged by PDF_SEO_LINK_FARM, suggesting a link farm or SEO poisoning attempt to drive traffic to potentially malicious sites.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=harvest+moon+a+wonderful+life+guide+ps4
    • https://static.usrfiles.com/ugd/b8c837_627bd5e6270a411586a7054f928fac01.pdf
    • https://static.usrfiles.com/ugd/b56239_214a827fa8914df4b94de89f4eac4046.pdf
    • https://static.usrfiles.com/ugd/97493d_dc33f63ab33a484997d506ad860bce6a.pdf
    • https://static.usrfiles.com/ugd/c8d394_6e93196eb391476f916c5f80f252cb09.pdf
    • https://static.usrfiles.com/ugd/b8c837_3beccebde3b047ee88b3fe86091f6146.pdf
    • https://cdn.shopify.com/s/files/1/0432/0778/6654/files/basic_knowledge_of_share_market.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/xubeke.pdf
    • https://static.usrfiles.com/ugd/122077_6134141fd55b4c3c8028c1063458f368.pdf
    • https://static.usrfiles.com/ugd/f0f215_ad8ec9c1e6704732b8d106f8cb790e95.pdf
    • https://static.usrfiles.com/ugd/1c8c6c_f1a2dae97f4541119f9c1a2d9be0d594.pdf
    • https://static.usrfiles.com/ugd/b8c837_008fd272bb57404784e4a5b0f62817a9.pdf
    • https://static.usrfiles.com/ugd/b8c837_9317eb29db70495d88f1b505263542c1.pdf
    • https://cdn.shopify.com/s/files/1/0438/5882/1285/files/ordering_fractions_with_different_denominators_worksheet_tes.pdf
    • https://cdn.shopify.com/s/files/1/0435/7727/8627/files/thai_on_arrival_visa_form.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000061dd.bin
533fad3c8cc191bce8d331b9f68d821354331978e0381a688fb0ca4d3dc2e3c5
pdf-font-stream PDF embedded font (sfnt) at offset 0x61DD 4664 bytes
font_01_sfnt_off0000722c.bin
7cd87336f3c64f5c955e49d3fe0c201169e18f7f53727e007c66e592a70363ac
pdf-font-stream PDF embedded font (sfnt) at offset 0x722C 5564 bytes
font_02_sfnt_off00008521.bin
3652c82d39e582c7dfcf0fd848357c330da32c174f3fefdf6ed3a19200e18ffa
pdf-font-stream PDF embedded font (sfnt) at offset 0x8521 10532 bytes