Malicious PDF — malware analysis report

Static analysis result for SHA-256 dff66ae46b6f7ad7…

MALICIOUS

PDF

38.5 KB Created: 2020-09-01 22:05:51 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 62a2e9441474e021313ee35c681c58d1 SHA-1: fa22998d37bd792a88906367a9bebddcb1641e74 SHA-256: dff66ae46b6f7ad7fb0c74216b5f291de4c4330c4ea509b0b8c41a72b32a2ea6
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, with one identified as a malicious redirector. The document body is heavily obfuscated but appears to contain references to the embedded URLs. This suggests the primary purpose is to direct users to potentially harmful external sites, likely for SEO spam or phishing.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=grammatical+mood+worksheet
    • https://static.usrfiles.com/ugd/e1c37d_d65b7f1560c24d4b96ceba5a18b2c384.pdf
    • https://static.usrfiles.com/ugd/c8a981_a8e63ed7857e470999c3c73c4c7da6f3.pdf
    • https://static.usrfiles.com/ugd/362633_923d6855da7f4400b5ec16fc09aa410e.pdf
    • https://cdn.shopify.com/s/files/1/0465/2154/8958/files/32628714069.pdf
    • https://cdn.shopify.com/s/files/1/0431/7079/1573/files/the_universe_colonizing_space_answers.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/vufofabiziterefabul.pdf
    • https://cdn.shopify.com/s/files/1/0436/6857/0265/files/castrol_edge_5w30_c3.pdf
    • https://cdn.shopify.com/s/files/1/0431/6502/4416/files/definite_integral_examples_and_answers.pdf
    • https://cdn.shopify.com/s/files/1/0431/0204/4316/files/50093803332.pdf
    • https://cdn.shopify.com/s/files/1/0440/7679/4021/files/42973802176.pdf
    • https://cdn.shopify.com/s/files/1/0433/2965/0843/files/jurnal_alkalinitas_air.pdf
    • https://cdn.shopify.com/s/files/1/0431/2160/6820/files/72381429952.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/61411835552.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000058c0.bin
ed7606d2e651cb98972c57500bd3d1a28a4c2a1a8c9beb1c93a97b1397c6ba0b
pdf-font-stream PDF embedded font (sfnt) at offset 0x58C0 5368 bytes
font_01_sfnt_off00006ae6.bin
71c3270177c2e87ae47e74b827399a71461a6c31a0b9ea244be0d8f3489d7b39
pdf-font-stream PDF embedded font (sfnt) at offset 0x6AE6 10180 bytes