Malicious PDF — malware analysis report

Static analysis result for SHA-256 d73e42f99785f33e…

MALICIOUS

PDF

45.1 KB Created: 2020-09-06 11:31:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7b2f1e16d7b2b45c19a1a17293520d86 SHA-1: 23866d6bc74f0b37d803e5b0f5eed302293eef20 SHA-256: d73e42f99785f33eb91026c419014d5e32ad6b0530aa803b6bc6f8140e8a00bb
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains numerous embedded links, with one specifically identified as a malicious redirector. The document body, though heavily obfuscated, contains text related to 'learning colors worksheets for kindergarten' and includes the malicious URL, suggesting a lure to disguise malicious activity. The presence of a link farm heuristic further supports the malicious intent of distributing links.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/pify?keyword=learning+colors+worksheets+for+kindergarten
    • https://static.usrfiles.com/ugd/f09a9d_d227301c98444f0aaa6451e34412c0b0.pdf
    • https://static.usrfiles.com/ugd/95089d_be5f4c317f254321926c3dd7b310ab6d.pdf
    • https://static.usrfiles.com/ugd/0779a3_1cb40df92b03481bab0ce29cf77f8006.pdf
    • https://static.usrfiles.com/ugd/bfbc46_714a8ccfbf0940bc8401b39732fa4bbf.pdf
    • https://static.usrfiles.com/ugd/d78803_df5d72ee56864233ae6761bfcb5ed7e1.pdf
    • https://static.usrfiles.com/ugd/ac0094_e91919118637482b9c483c8b6a5123d9.pdf
    • https://static.usrfiles.com/ugd/fb5067_7578d3818cd748cebf1a44b565621dfb.pdf
    • https://static.usrfiles.com/ugd/b50c55_dbf6c744727d45c7872462b1ab7f8245.pdf
    • https://static.usrfiles.com/ugd/60933b_8b73a66addc54732baa267f66594bb2c.pdf
    • https://static.usrfiles.com/ugd/ee6770_322bd522a1aa42268adacc87c882e157.pdf
    • https://static.usrfiles.com/ugd/b8c837_fea7b79cd52c4594bcfd75c3de00e607.pdf
    • https://static.usrfiles.com/ugd/338562_98c2fbcfd205416092f85cae0003897a.pdf
    • https://static.usrfiles.com/ugd/76de1a_a30a2c868ccc4f5ab233b23f5acc8685.pdf
    • https://cdn.shopify.com/s/files/1/0433/5727/4261/files/weather_report_for_fairport_ny.pdf
    • https://cdn.shopify.com/s/files/1/0431/6689/2181/files/product_rule_derivative_worksheet.pdf
    • https://cdn.shopify.com/s/files/1/0433/6690/8054/files/setubuvunopoxilofovikapex.pdf
    • https://cdn.shopify.com/s/files/1/0434/5564/3813/files/83514446961.pdf
    • https://cdn.shopify.com/s/files/1/0430/7940/1632/files/99880610961.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006b96.bin
2cd0167f995b3bd65236792a10fc9b99cce0927844ffe2383e29fcd985c06ae5
pdf-font-stream PDF embedded font (sfnt) at offset 0x6B96 5380 bytes
font_01_sfnt_off00007df4.bin
0821bef50fee48ba65617a6958a3cdbcab375181678c16bb1e46794a85ef9d28
pdf-font-stream PDF embedded font (sfnt) at offset 0x7DF4 13044 bytes