Malicious PDF — malware analysis report

Static analysis result for SHA-256 f30fde7b300d9ce6…

MALICIOUS

PDF

48.9 KB Created: 2020-09-07 00:48:55 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d5701fa3e5ad560a3f8aaf852b286e97 SHA-1: 6d2c3676ae57790548aafe420cc17f182c7ec63f SHA-256: f30fde7b300d9ce6c87c9a299d5a30c264cad80fc78aea6ba5ea63a9bdb09c87
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a critical heuristic indicating it links to known malicious redirector infrastructure. It also exhibits a link farm pattern, suggesting an attempt to game search engines or distribute malicious links. The document body, though heavily obfuscated, contains the URL that triggered the malicious redirector heuristic. No scripts were extracted from this sample.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=accelerated+stability+studies+ich+guidelines
    • https://static.usrfiles.com/ugd/8acad3_f015ee0e4eab42b19a84cbff27c824c0.pdf
    • https://static.usrfiles.com/ugd/5ea4d5_81fd3efdad604cedb36c05a0834c5da5.pdf
    • https://static.usrfiles.com/ugd/12dc78_d1e44af9cc204b24bf8891192645a236.pdf
    • https://static.usrfiles.com/ugd/b8c837_2810cdd32c5249599da4891bfd40db03.pdf
    • https://static.usrfiles.com/ugd/a382ee_ac7862c8458c42a0a9b5697fd2bc685d.pdf
    • https://static.usrfiles.com/ugd/1479de_6f591a301ca44402afba718b4d5c607f.pdf
    • https://static.usrfiles.com/ugd/b8c837_c73cfb7d4e44477f809a204966db6af4.pdf
    • https://static.usrfiles.com/ugd/510691_ba5d4110d26e4496af6b0cbb665abd24.pdf
    • https://static.usrfiles.com/ugd/455f95_c56db8f915404c7382618509f9116e57.pdf
    • https://static.usrfiles.com/ugd/bf650e_64e1362916e84d6580cb2640521271bb.pdf
    • https://static.usrfiles.com/ugd/7e6083_8d65922279654300a6ca73b6114d7b37.pdf
    • https://static.usrfiles.com/ugd/bd7df1_60460a8a34f94624b6065b8bca72e387.pdf
    • https://static.usrfiles.com/ugd/9a242c_bbb697bf55044b5c9403b7ff1da27600.pdf
    • https://static.usrfiles.com/ugd/b8c837_f69efc7993d64722bb3375252cf638f6.pdf
    • https://static.usrfiles.com/ugd/b8c837_aa86e560b5d84967a8f05fbf899b2897.pdf
    • https://static.usrfiles.com/ugd/a1fb72_f1ddb13b55bc4ae7898ea3607bce9021.pdf
    • https://static.usrfiles.com/ugd/db1da1_30b6da044b8b433a9c05aabda0a913fa.pdf
    • https://static.usrfiles.com/ugd/64f9d2_d6c7f1389e794382b480cabfb1f52663.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000764e.bin
5d53bb52bbad0c9c2a945120f3815651915eca8e4a0c41f7163aaf4756ad3149
pdf-font-stream PDF embedded font (sfnt) at offset 0x764E 1584 bytes
font_01_sfnt_off00007e56.bin
f05ffdd43a13a1f3476bf192d89fe18ddc4d75595837b92ede5eee36345c9831
pdf-font-stream PDF embedded font (sfnt) at offset 0x7E56 5432 bytes
font_02_sfnt_off000090cf.bin
f53c65a4a4dc5d6a25056cb5ffacb8dc4128500bae6a827699a933f706beb9aa
pdf-font-stream PDF embedded font (sfnt) at offset 0x90CF 10804 bytes