Malicious PDF — malware analysis report

Static analysis result for SHA-256 de9446ea886680b9…

MALICIOUS

PDF

41.5 KB Created: 2020-08-31 08:21:50 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 406e713758e98ac31f34b5c24de04733 SHA-1: 9c5cbebb0102cd17711c38fb1c86346c46b67ef7 SHA-256: de9446ea886680b96cdd38d26283ca012c2b17aec101da1b4255ed865b10a700
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a significant number of embedded links, identified as a link farm. One of these links, 'https://ttraff.cc/wix?keyword=elias+oraba+en+el+monte+carmelo+con+letra', points to known malicious redirector infrastructure. The document body, though partially garbled, also contains this URL, suggesting it's intended to be presented to the user. The primary attack pattern is likely to lure users into clicking these links, leading them to malicious sites.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=elias+oraba+en+el+monte+carmelo+con+letra
    • https://static.usrfiles.com/ugd/eb5a6a_7dad6b6e84ae4e9e855baea93b28a7ed.pdf
    • https://static.usrfiles.com/ugd/b8c837_b822286d2aa142f49455f67b8496307b.pdf
    • https://static.usrfiles.com/ugd/05900a_776ff052847f48ba8d38736782589e6a.pdf
    • https://static.usrfiles.com/ugd/b8c837_347cf763950a493295616fa879c9376d.pdf
    • https://static.usrfiles.com/ugd/b8c837_b43b10d13710497bb1d1f064c5cd565d.pdf
    • https://static.usrfiles.com/ugd/b8c837_3b60954656eb4c149fba766bfe93ab8f.pdf
    • https://static.usrfiles.com/ugd/868401_c4734f2dfe964575b57b5b819d7dc5cf.pdf
    • https://static.usrfiles.com/ugd/b8c837_98354f1194a24134a6492c032af1aa61.pdf
    • https://static.usrfiles.com/ugd/b8c837_b92030c7ddb24f22bdaf166238472d78.pdf
    • https://static.usrfiles.com/ugd/f1780b_d5424dcb16834c73b4c41b8f767f45d1.pdf
    • https://static.usrfiles.com/ugd/868401_844d9c9bb73c42ae9331c2cf57019c26.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005235.bin
597f8c99e26be43fa1c97853f84884cb1e32d20b46412d61372085e131bab5ce
pdf-font-stream PDF embedded font (sfnt) at offset 0x5235 3984 bytes
font_01_sfnt_off00006047.bin
8c13ecd6e3e0bfa36e7164bf410e1ae45ecc6fa3dcd4020fd005f40b37c62b10
pdf-font-stream PDF embedded font (sfnt) at offset 0x6047 5040 bytes
font_02_sfnt_off00007152.bin
15a98c527fcf9228c046c5697433f4b888bd09aecdc9a996e885244d6906950b
pdf-font-stream PDF embedded font (sfnt) at offset 0x7152 11824 bytes