Malicious PDF — malware analysis report

Static analysis result for SHA-256 de734e010734f4e2…

MALICIOUS

PDF

48.0 KB Created: 2020-08-12 08:45:37 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6ae70a6b94ec3d967e36b147a0f7b91c SHA-1: afc0d8786ba93e26c362e0e275db21bf5cc2c050 SHA-256: de734e010734f4e289bc29f333407ee8f0f5cc068339f5519885f608bbecfe89
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link farm designed to lure users into downloading more PDFs, with one primary link redirecting to malicious infrastructure. The heuristic PDF_MALICIOUS_REDIRECTOR_LINK indicates that the initial URL leads to known malicious redirector infrastructure. The document body, though heavily obfuscated, contains the primary malicious URL. No scripts were extracted from this sample.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=design+methods+in+architecture+pdf
    • http://files.power-up-potential.com/uploads/1/3/1/3/131379875/foludajijeduj.pdf
    • http://xuvoda.humblegritsales.com/uploads/1/3/0/7/130739289/mawodapuxoridum_rozaj.pdf
    • http://jemas.1stonthreads.com/uploads/1/3/1/4/131438177/xexubolegatowe.pdf
    • http://files.pentecostalcchurch.com/uploads/1/3/1/4/131437402/widajewitol_nadelirokilax.pdf
    • https://cdn.shopify.com/s/files/1/0432/6588/4323/files/50582971535.pdf
    • https://cdn.shopify.com/s/files/1/0453/2695/8747/files/transistor_amplifier_circuit_diagram.pdf
    • https://cdn.shopify.com/s/files/1/0430/6590/1210/files/zaxaruzaladulul.pdf
    • https://cdn.shopify.com/s/files/1/0431/8062/1984/files/rawemevolewutexofe.pdf
    • https://cdn.shopify.com/s/files/1/0430/5531/7149/files/morexizovigun.pdf
    • https://cdn.shopify.com/s/files/1/0429/9656/4131/files/18589502317.pdf
    • https://cdn.shopify.com/s/files/1/0437/2670/0696/files/fifavixasuvalufotepuziv.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/55864873889.pdf
    • https://cdn.shopify.com/s/files/1/0432/6978/3720/files/monografia_sobre_meio_ambiente.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/tizerosotusalasebix.pdf
    • https://cdn.shopify.com/s/files/1/0439/4529/6027/files/zelavidisalajulex.pdf
    • https://cdn.shopify.com/s/files/1/0432/0811/4340/files/jisivabodavokibifativa.pdf
    • https://cdn.shopify.com/s/files/1/0429/6844/9180/files/kivavikemudazitonikesagut.pdf
    • https://cdn.shopify.com/s/files/1/0432/8855/9780/files/69357743257.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006e58.bin
3adabff876b995c7c850cff82a37369e03cb9acc5dbaf563e53af3e3aedc42c3
pdf-font-stream PDF embedded font (sfnt) at offset 0x6E58 5416 bytes
font_01_sfnt_off00008092.bin
8050b3e479be8d7f9f91cdb401558c419d94a6d40c634f5efbb455e8cbf4eed2
pdf-font-stream PDF embedded font (sfnt) at offset 0x8092 10760 bytes
font_02_sfnt_off0000a4b8.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0xA4B8 4324 bytes