Malicious PDF — malware analysis report

Static analysis result for SHA-256 19b9cbcb507c15ed…

MALICIOUS

PDF

39.6 KB Created: 2020-08-30 16:19:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9ad70fbcf3abecf75c431b6cdda0dd51 SHA-1: 2c18495421432a0b8883186aabdb1c39c533a160 SHA-256: 19b9cbcb507c15ed45668beb63e7b48c21709929cc00467c273f0dad427a1e61
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.cc/wix?keyword=tomb+raider+apk+data'. This URL is presented in a context that suggests a lure for downloading potentially malicious content. The document also contains a large number of embedded links to external PDFs, many hosted on 'static.usrfiles.com', indicating a link farm strategy to obscure the malicious destination. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=tomb+raider+apk+data
    • https://static.usrfiles.com/ugd/b8c837_fcb8cec071e747509494258195b98e83.pdf
    • https://static.usrfiles.com/ugd/83f04e_b1a1cb6a75d84b0997b4c40d3caeecd3.pdf
    • https://static.usrfiles.com/ugd/b8c837_87cbba97ed3043f890761bdf6991f9dd.pdf
    • https://static.usrfiles.com/ugd/b8c837_60aefdf27c8640259bb89050a311a25f.pdf
    • https://static.usrfiles.com/ugd/735189_d97375d7d4af47a08f41c1c73da65ec6.pdf
    • https://static.usrfiles.com/ugd/b8c837_2c3ccf94e199499b9bd50393b5a930bd.pdf
    • https://static.usrfiles.com/ugd/3bf302_3e3f10cb61114fbeb79d488d299538d5.pdf
    • https://static.usrfiles.com/ugd/bfbc46_f734d63d17b34ddb8fea5f0fe7384441.pdf
    • https://static.usrfiles.com/ugd/b8c837_e7651669e1064a968952ffd9e7985694.pdf
    • https://static.usrfiles.com/ugd/1cfe37_d361910f92e84e4a9f42a5cd117a53e3.pdf
    • https://static.usrfiles.com/ugd/97aff7_838131e212024c04b704a083502f14a3.pdf
    • https://static.usrfiles.com/ugd/9b33c5_3a7f95782912484bb54dbb9a8e05ceaf.pdf
    • https://static.usrfiles.com/ugd/b8c837_ffee06910d8b4c089bd896cc3b6c75a7.pdf
    • https://static.usrfiles.com/ugd/b8c837_bc08f15142aa476e932659dbf9068f2d.pdf
    • https://static.usrfiles.com/ugd/b8c837_da9089b82e744d2498ab6fadc3cd9248.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005da8.bin
cec5547ea9be39d808eb1f070577aa710ea3bd264f24bd9452f340b8c34001dc
pdf-font-stream PDF embedded font (sfnt) at offset 0x5DA8 5048 bytes
font_01_sfnt_off00006ebb.bin
8fdf338c1b54226e15a3988df61e96ad0b4ed1e5a6f5bad392db9b9f8bc839cb
pdf-font-stream PDF embedded font (sfnt) at offset 0x6EBB 10284 bytes