Malicious PDF — malware analysis report

Static analysis result for SHA-256 ac42f13394c79c3a…

MALICIOUS

PDF

47.9 KB Created: 2020-08-21 08:09:35 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 44d62624761dbb47f4418922b7fbe1b7 SHA-1: c3138211fd07ecec75c243f648925fdcb7ec8a3b SHA-256: ac42f13394c79c3a89eac7c570f4a62cd4eeaeef8357e3f5d49f32e4f950a130
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link farm and a malicious redirector pointing to a lure for 'Asphalt 8 airborne hack unlimited money'. The document body, though heavily obfuscated, contains references to this lure and the redirector URL. The presence of numerous external PDF links suggests an attempt to manipulate search engine results or distribute further malicious content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=asphalt+8+airborne+hack+unlimited+money
    • http://jizir.brookeorphanage.com/uploads/1/3/0/8/130814328/jexesilozenig.pdf
    • http://files.thesocialprof.com/uploads/1/3/2/7/132712614/nokuv.pdf
    • http://files.mvhsphotography.com/uploads/1/3/2/7/132740716/podirunikopezewalani.pdf
    • http://sawul.weweresosmall.com/uploads/1/3/0/9/130969723/2564032.pdf
    • http://files.shannon-nightingale.com/uploads/1/3/1/0/131069934/7500009.pdf
    • https://cdn.shopify.com/s/files/1/0438/3608/0288/files/92651926193.pdf
    • https://cdn.shopify.com/s/files/1/0429/9682/6273/files/revumoxeso.pdf
    • https://cdn.shopify.com/s/files/1/0431/0191/3244/files/53945970798.pdf
    • https://cdn.shopify.com/s/files/1/0440/4733/5589/files/59612760863.pdf
    • https://cdn.shopify.com/s/files/1/0447/6190/7351/files/que_son_las_tecnologias_de_la_informacion_y_comunicacion.pdf
    • https://cdn.shopify.com/s/files/1/0435/7016/7967/files/server_training_manual_template.pdf
    • https://cdn.shopify.com/s/files/1/0428/9606/4671/files/20320231574.pdf
    • https://cdn.shopify.com/s/files/1/0434/0088/8483/files/cisco_wifi_access_point.pdf
    • https://cdn.shopify.com/s/files/1/0431/7016/8986/files/wukilewejigib.pdf
    • https://cdn.shopify.com/s/files/1/0431/8153/9483/files/47431419686.pdf
    • https://cdn.shopify.com/s/files/1/0431/4634/6658/files/1107271907.pdf
    • https://cdn.shopify.com/s/files/1/0428/3714/7804/files/lives_of_the_prophets_anwar_al_awlaki.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/vemuvuferakodumi.pdf
    • https://cdn.shopify.com/s/files/1/0428/5107/4214/files/54319220235.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006dfe.bin
da0fd6f2ef4cb84ef9a7f3968b430e028804c0e67ee389626712bd59017543bf
pdf-font-stream PDF embedded font (sfnt) at offset 0x6DFE 5684 bytes
font_01_sfnt_off0000810d.bin
5258525de55224fd9fb4a91bcd5c3ed9212d5f18c144dd2f4dced26f73026f2f
pdf-font-stream PDF embedded font (sfnt) at offset 0x810D 10400 bytes
font_02_sfnt_off0000a41d.bin
d1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378
pdf-font-stream PDF embedded font (sfnt) at offset 0xA41D 4324 bytes