Malicious PDF — malware analysis report

Static analysis result for SHA-256 e613f198399de10f…

MALICIOUS

PDF

42.0 KB Created: 2020-09-17 19:49:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3ee15a10420ea14069cc6af13148518c SHA-1: f54caa0bf0cdb48b8e03125bc7d636cf91960c18 SHA-256: e613f198399de10fe13f251e125faa0f32fe1d0bc20fe0ad95e4a14f14e0da5c
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing indicating it is a malicious redirector link, specifically pointing to a URL that uses a school calendar keyword. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded URLs pointing to external PDF files, many of which are hosted on suspicious domains. The document body itself contains the keyword 'lee county ga school calendar 2019-20' and several URLs, reinforcing the lure. The primary malicious URL identified is https://ttraff.club/pify?keyword=lee+county+ga+school+calendar+2019-20, which likely serves as a gateway to further malicious content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/pify?keyword=lee+county+ga+school+calendar+2019-20
    • http://files.brand-bullets.com/uploads/1/3/2/7/132711983/5929752.pdf
    • http://files.clearhrsolutionsd.com/uploads/1/3/1/4/131406258/jibuniliko-tibemagin.pdf
    • http://vovagoro.freedomridesmuseumfriends.org/uploads/1/3/1/4/131437812/namerilumumono_rafer_vuxefoxe_buruvadagobewop.pdf
    • http://nubuti.braydenyork.com/uploads/1/3/0/7/130775354/gavipovesa-tarezebatubiguz.pdf
    • http://files.personalspaceproject.com/uploads/1/3/2/7/132740343/piwepapefa-kavijabojexopi-fuwuwumewa.pdf
    • https://cdn.shopify.com/s/files/1/0436/0326/3650/files/mossberg_500_for_sale_walmart.pdf
    • https://cdn.shopify.com/s/files/1/0434/3611/4076/files/background_images_free_zip.pdf
    • https://cdn.shopify.com/s/files/1/0431/0515/7282/files/vuboxupazelusikejibesotu.pdf
    • https://cdn.shopify.com/s/files/1/0434/2936/3878/files/antibiotics_chemistry_project.pdf
    • https://cdn.shopify.com/s/files/1/0459/9529/4887/files/69833318735.pdf
    • https://cdn.shopify.com/s/files/1/0432/1309/5067/files/78684663398.pdf
    • https://cdn.shopify.com/s/files/1/0430/7720/6167/files/67531304089.pdf
    • https://cdn.shopify.com/s/files/1/0433/4786/9850/files/guzizuvusikem.pdf
    • https://cdn.shopify.com/s/files/1/0437/8886/1602/files/14604502857.pdf
    • https://cdn.shopify.com/s/files/1/0432/6811/2550/files/adobe_animation_cc_software_free.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006257.bin
acce6c9dd39543d368f4b25890c66f9484b821e2d0d53e0ed22e7ba2aeb90a90
pdf-font-stream PDF embedded font (sfnt) at offset 0x6257 5760 bytes
font_01_sfnt_off000075fe.bin
91780a987d36a20185b2a3aabd1f3c6aa5e6b204862c16cfd48e7f434b85a676
pdf-font-stream PDF embedded font (sfnt) at offset 0x75FE 10900 bytes