Malicious PDF — malware analysis report

Static analysis result for SHA-256 c7a1eb43bacf8871…

MALICIOUS

PDF

62.0 KB Created: 2020-09-18 03:21:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8950d4756b4b65c2aef02498d70aa341 SHA-1: 268143fd2440f09f5d3b6325c527ea9e472ea876 SHA-256: c7a1eb43bacf8871bb88b09d5fa6074516f42bbc7a6eedb69bf7b399d1231e42
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, with one specifically identified as a malicious redirector. The document body, though heavily obfuscated, contains the same suspicious URL. This suggests the primary purpose of the document is to lure the user into clicking malicious links, likely leading to further compromise.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=best+girl+tsum+tsum+for+coins
    • https://ecb6ec91-d205-46e3-a42e-f2bbf6dd3b3e.filesusr.com/ugd/97aff7_537c563ab7d04cdf93b8d625e703c16c.pdf?index=true
    • https://dbdac1f8-7135-4652-8017-8324f0f36636.filesusr.com/ugd/5ea4d5_5693e37fd7204b6da44f63cef7975292.pdf?index=true
    • https://79efc1db-54a5-479c-b269-c337ae0e349a.filesusr.com/ugd/a31856_553f0d4ba3144402b58188fee4558235.pdf?index=true
    • https://d5a66967-f923-48e6-bfb2-d5118cdad63e.filesusr.com/ugd/4cd51e_65e51b70b72b4d5b97b1bb42feefe86c.pdf?index=true
    • https://a62191bb-c70c-40f6-b5a0-a04df4d930c0.filesusr.com/ugd/99965f_e2e2bcc4711a484ea45767e7e535911b.pdf?index=true
    • https://88d51e1b-07a5-42ba-bf8a-9e88e42f3087.filesusr.com/ugd/3be3a7_97789fb6cff1428197b17e0cfd21c483.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0483/7857/7045/files/60387607151.pdf
    • https://cdn.shopify.com/s/files/1/0431/7881/9735/files/rezoxeniwilurivan.pdf
    • https://cdn.shopify.com/s/files/1/0430/1812/5465/files/55554477600.pdf
    • https://cdn.shopify.com/s/files/1/0440/4848/2454/files/livuzatusagenifinonaku.pdf
    • https://cdn.shopify.com/s/files/1/0433/9764/4449/files/aarrow_becton_bunny_manual.pdf
    • https://da0bf135-5b2b-4e45-9311-c174bca9b579.filesusr.com/ugd/86319b_8c9a0aec42f94c4782cca52fc80de295.pdf?index=true
    • https://061ef07f-4b98-4765-83c1-628e5dddf232.filesusr.com/ugd/31bf02_a747fb899e7348659ae61b4a6bcbe9ac.pdf?index=true
    • https://35adcc7f-09fc-49bc-9e9a-336a6927f8b8.filesusr.com/ugd/e4ee87_3ad29c37d8ce4b2c90d041ca3146eaa8.pdf?index=true
    • https://57a35d38-ee79-4337-bf67-8e48a00e1a41.filesusr.com/ugd/24deb6_20fb2ba7b8f146d0be0bdd59c9a7fddd.pdf?index=true
    • https://e5e475a3-6e66-466b-908c-74b156db5cfa.filesusr.com/ugd/46bfb0_fbd6e959227c4adda59c9e7c5b3b49c4.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006b81.bin
25390a64d224b84456f74066bc1e3e46dbb3ff37aeecb5b2b3fafa66314b9aac
pdf-font-stream PDF embedded font (sfnt) at offset 0x6B81 7680 bytes
font_01_sfnt_off00008584.bin
cab31b8c728eb50d70e54ff4ea51ab4fd2a8842ac77ec7d146673bdc1a16edca
pdf-font-stream PDF embedded font (sfnt) at offset 0x8584 5040 bytes
font_02_sfnt_off0000969b.bin
95aacf522b6ffb9790aaf9bac6e915529f5f4968e46316ba61edae1e5acbf85e
pdf-font-stream PDF embedded font (sfnt) at offset 0x969B 3748 bytes
font_03_sfnt_off0000a4c7.bin
09af3dd2c39dbf58977f51bed57d958e0edb457d4dd4ef42a789b39491c36ef2
pdf-font-stream PDF embedded font (sfnt) at offset 0xA4C7 14992 bytes
font_04_sfnt_off0000d360.bin
eee80f15c7c0a6bc8cdecda1d85630f5b5769c8a82e7748a05f05f4335d512f3
pdf-font-stream PDF embedded font (sfnt) at offset 0xD360 16560 bytes