Malicious PDF — malware analysis report

Static analysis result for SHA-256 bb821a1c6adaf5f8…

MALICIOUS

PDF

47.9 KB Created: 2020-07-10 01:14:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 88cfd6c3a39340103dd860deb12597e6 SHA-1: cb76a17d374f7130a0a14fed93079982814ea282 SHA-256: bb821a1c6adaf5f8a806ee7d2b5ab6f84a5e84390ce8d4fbd1678afc78818221
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, many of which point to external PDF files hosted on various domains. One prominent link redirects to a known malicious infrastructure at 'ttraff.ru'. The document body, while containing garbled text, also includes the same worksheet title and the initial malicious URL, reinforcing the lure. The primary attack pattern involves directing users to potentially harmful websites through a link farm disguised as educational content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wb?keyword=crash%20course%20biology%20water%20liquid%20awesome%20worksheet%20answers
    • http://files.coachinginyourcloset.com/uploads/1/3/0/7/130776370/cc603903632.pdf
    • http://files.goodstuffprimaryresources.com/uploads/1/3/2/6/132681204/lamumolop.pdf
    • http://files.addaihealthedu.net/uploads/1/3/1/3/131380618/2087346.pdf
    • http://files.wlcbands.com/uploads/1/3/1/6/131607712/2769e0d94.pdf
    • http://files.jessicadenham.com/uploads/1/3/2/7/132712005/molavavip.pdf
    • http://files.cailenfu.com/uploads/1/3/1/4/131437444/rutez_wubusaxofab_kajali_zuwogor.pdf
    • http://files.twoforestplaza-leasing.com/uploads/1/3/1/3/131378921/2856213.pdf
    • http://files.mastercreatorsadventureretreat.com/uploads/1/3/1/4/131437091/bizitesukoratinov.pdf
    • http://files.nessasgoodiesshop.com/uploads/1/3/1/6/131606280/gizemazilowujonawit.pdf
    • http://files.pemmensgolf.net/uploads/1/3/1/3/131379612/febokibilodirina.pdf
    • https://guzebamukubu.files.wordpress.com/2020/06/kukafoxevekilipeloxa.pdf
    • https://gunurineso.files.wordpress.com/2020/06/vetinefupibosivezuxob.pdf
    • https://gapekapanad.files.wordpress.com/2020/06/61686672361.pdf
    • https://vezumore.files.wordpress.com/2020/07/28929223944.pdf
    • https://sivutis.files.wordpress.com/2020/06/soxolabanigab.pdf
    • https://duwadunox.files.wordpress.com/2020/06/81556021637.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/43561311815.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/mubexuv.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/28391359898.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007c0b.bin
0182a5759367d32cc0dd8c051d55ef262afd9a65b101a0b190d6cd9f82289f73
pdf-font-stream PDF embedded font (sfnt) at offset 0x7C0B 5780 bytes
font_01_sfnt_off00008f99.bin
388c32ca9906552590088b3eee442d300213213c3ff6a8d2a9eb53e82e34455f
pdf-font-stream PDF embedded font (sfnt) at offset 0x8F99 9996 bytes