Malicious PDF — malware analysis report

Static analysis result for SHA-256 f30e4e1a683dea29…

MALICIOUS

PDF

56.7 KB Created: 2020-10-21 11:40:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3abaeba3890f5b966972ab223f17a1ac SHA-1: faae92c926b705df8d279cd2c353de9cc87d3b1f SHA-256: f30e4e1a683dea293a38e68f729bf62398812fd0c48b348f32d3738522ea6b4a
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.link/123?keyword=manejo+de+preeclampsia+y+eclampsia+pdf'. This URL is presented within the document body, disguised as a PDF related to medical information. The presence of a link farm heuristic further indicates malicious intent to distribute links. No scripts were extracted from this sample.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/123?keyword=manejo+de+preeclampsia+y+eclampsia+pdf
    • https://cdn-cms.f-static.net/uploads/4366044/normal_5f86f82adebc0.pdf
    • https://cdn-cms.f-static.net/uploads/4368466/normal_5f8a6a927ab98.pdf
    • https://cdn-cms.f-static.net/uploads/4381320/normal_5f8b791d6da58.pdf
    • https://cdn-cms.f-static.net/uploads/4371266/normal_5f8867f8c6fd9.pdf
    • https://cdn-cms.f-static.net/uploads/4365545/normal_5f88cc5f11f4d.pdf
    • https://cdn-cms.f-static.net/uploads/4378607/normal_5f8a4f33ba858.pdf
    • https://cdn-cms.f-static.net/uploads/4380540/normal_5f8b23de53488.pdf
    • https://cdn-cms.f-static.net/uploads/4378836/normal_5f8e24b447a57.pdf
    • https://cdn-cms.f-static.net/uploads/4366965/normal_5f8c77fa9f499.pdf
    • https://cdn-cms.f-static.net/uploads/4373259/normal_5f8d284d7d81d.pdf
    • https://cdn.shopify.com/s/files/1/0493/1675/7663/files/26490367592.pdf
    • https://cdn.shopify.com/s/files/1/0484/6898/3969/files/compound_sentence_worksheet_for_grade_4.pdf
    • https://cdn.shopify.com/s/files/1/0478/4055/9263/files/analysis_of_themes_in_macbeth.pdf
    • https://cdn.shopify.com/s/files/1/0457/3783/6710/files/somagulumujonixefu.pdf
    • https://cdn.shopify.com/s/files/1/0433/0147/0366/files/9204477422.pdf
    • https://s3.amazonaws.com/tadovu/trauma_psicologico.pdf
    • https://s3.amazonaws.com/memul/mojamivetivoledite.pdf
    • https://s3.amazonaws.com/kavitokolezub/82772320883.pdf
    • https://s3.amazonaws.com/leguvefu/lutijut.pdf
    • https://cdn.shopify.com/s/files/1/0432/7967/9656/files/active_passive_sentences_exercises.pdf
    • https://cdn.shopify.com/s/files/1/0483/5799/8743/files/differentiated_instruction_definition.pdf
    • https://cdn.shopify.com/s/files/1/0478/6061/3286/files/android_get_screen_capture_programmatically.pdf
    • https://s3.amazonaws.com/wonoti/tukanafimujamosirurawas.pdf
    • https://s3.amazonaws.com/susopuzupure/fixukomemok.pdf
    • https://s3.amazonaws.com/felasorarabipis/square_of_numbers_from_1_to_50.pdf
    • https://s3.amazonaws.com/wonoti/13129028543.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com/s/fi

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00009f87.bin
4df7c715432b91fc68f3c04a4de50b7130d4ef9e3c8b9e53e0788a4a14bd2060
pdf-font-stream PDF embedded font (sfnt) at offset 0x9F87 5484 bytes
font_01_sfnt_off0000b227.bin
32ceb7717f85895e65de66056169d3ef46562a6d400f5e8e8a28e2584b2143e2
pdf-font-stream PDF embedded font (sfnt) at offset 0xB227 10284 bytes