Malicious PDF — malware analysis report

Static analysis result for SHA-256 c8de3562464f3639…

MALICIOUS

PDF

41.6 KB Created: 2020-08-31 05:52:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 73e1518f7208aaab7d9d0ffe6027f37e SHA-1: a3c3d5a826892918c1165c217a5e562077733e4c SHA-256: c8de3562464f3639c244a5716e8408abcfd0400e333fbdd20940ecf0631e4c5c
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing for a malicious redirector link, pointing to a URL that includes "joint last will and testament template" in its query parameters. This suggests a social engineering lure to trick users into clicking the link. The file also exhibits characteristics of a PDF link farm, with numerous external links, many of which point to benign PDF files. The primary malicious IOC is the redirector URL, which likely leads to further malicious content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=joint+last+will+and+testament+template
    • https://static.usrfiles.com/ugd/5ecadc_ac99bdfac8f3429e9bdbec8761dc4998.pdf
    • https://static.usrfiles.com/ugd/b8c837_958296bf50a54ab59f4d998d3d98c7f3.pdf
    • https://static.usrfiles.com/ugd/895bef_b1601ddb9be243378546e02cf206774c.pdf
    • https://static.usrfiles.com/ugd/b8c837_68a5d3c55f344a95a4998d1bb1290c7a.pdf
    • https://static.usrfiles.com/ugd/d902bb_ac22e59843ea4d88854a80a10019af41.pdf
    • https://cdn.shopify.com/s/files/1/0427/5719/3895/files/lezufutuvo.pdf
    • https://cdn.shopify.com/s/files/1/0431/8792/9252/files/geometric_proofs_worksheet_with_answers.pdf
    • https://cdn.shopify.com/s/files/1/0431/1118/6588/files/busojuw.pdf
    • https://cdn.shopify.com/s/files/1/0438/2585/6672/files/cambridge_igcse_mathematics_core_and_extended_4th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0431/8769/9876/files/ansys_electronics_desktop_tutorial.pdf
    • https://cdn.shopify.com/s/files/1/0428/7866/4867/files/colchester_sixth_form_college_term_dates.pdf
    • https://cdn.shopify.com/s/files/1/0439/4336/2715/files/wefusolezisepido.pdf
    • https://cdn.shopify.com/s/files/1/0463/0272/4253/files/jafixadoviw.pdf
    • https://static.usrfiles.com/ugd/735189_d43309a85eab4264a3f6e035065dc99b.pdf
    • https://static.usrfiles.com/ugd/affb4a_a93a8647fb074a50abe891426dca1058.pdf
    • https://static.usrfiles.com/ugd/b8c837_17a5fc63bfaa451aaf22abc72bd1edbe.pdf
    • https://static.usrfiles.com/ugd/8b97dd_ae5453cf6c2c487ea598321e1c47dc72.pdf
    • https://static.usrfiles.com/ugd/ca32a8_58306048319f4b20a63eb5d5ec6501b1.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006670.bin
44ab1d574164c0b79790aa4b5003fbbd3eb4cd6fdd2f102e4a92f79422c689ed
pdf-font-stream PDF embedded font (sfnt) at offset 0x6670 5088 bytes
font_01_sfnt_off000077b8.bin
01138432fba7d266760d5e1abddb686bdf5f81c16fe178cc5b0a091da46c2f54
pdf-font-stream PDF embedded font (sfnt) at offset 0x77B8 9920 bytes