Malicious PDF — malware analysis report

Static analysis result for SHA-256 1e09e3b38a46a9e4…

MALICIOUS

PDF

49.4 KB Created: 2020-09-05 06:56:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8cef215223f7e8d4fbc709d7e8256d38 SHA-1: 2165487a4ef88bfeab8a525862d017ae1b602ab8 SHA-256: 1e09e3b38a46a9e4d8e432345ad93d99b0d55bcd38cf292665a8e3c2d0a552b8
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, directing users to 'https://ttraff.club/wix?keyword=af+soomaali+fasalka+3aad+pdf'. Additionally, it exhibits characteristics of a PDF link farm, with numerous external links, many pointing to 'static.usrfiles.com'. The document body, though heavily obfuscated, contains the same redirector URL, reinforcing the malicious intent. The primary goal appears to be redirecting users to malicious infrastructure.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=af+soomaali+fasalka+3aad+pdf
    • https://static.usrfiles.com/ugd/7a13df_4f6cc781527d4a4e8fcef6a144542cbf.pdf
    • https://static.usrfiles.com/ugd/50c35f_04d6108afec641bda7e37866401c6eaa.pdf
    • https://static.usrfiles.com/ugd/0adedf_f571871a291c416fb44f0ddf8be8a6a9.pdf
    • https://static.usrfiles.com/ugd/5438e3_f8f6d4405f74436e8fd96d1a65441e9a.pdf
    • https://static.usrfiles.com/ugd/80c1db_4028918c55744d248e87d7a62acf3a9e.pdf
    • https://static.usrfiles.com/ugd/b42fd6_fd88f471b928433cb83cb92d755ca32e.pdf
    • https://cdn.shopify.com/s/files/1/0432/3092/0871/files/85718760374.pdf
    • https://cdn.shopify.com/s/files/1/0437/3646/5559/files/java_paint_program.pdf
    • https://cdn.shopify.com/s/files/1/0427/8249/0791/files/71069254223.pdf
    • https://cdn.shopify.com/s/files/1/0445/9390/5828/files/date_object_javascript.pdf
    • https://static.usrfiles.com/ugd/429b25_f0703aba73c743ae91fcee3d8c039382.pdf
    • https://static.usrfiles.com/ugd/b3bc21_3d34a02f93624373a78a38e2d30da6f4.pdf
    • https://static.usrfiles.com/ugd/fb41f9_19189ae0506e46049ad54fd5ed66a8f2.pdf
    • https://static.usrfiles.com/ugd/455f95_4ca0fcf6e4e742f18c3266f7f595eb61.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007f68.bin
a69f0ea7184ed656e6bff0dab4ae1b89166262e7b8068e29343cb5a67f116839
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F68 5308 bytes
font_01_sfnt_off0000916b.bin
523bf1fb23c06e5377ed822c2db9a880d242ff0e10f9a986e43490c00182e756
pdf-font-stream PDF embedded font (sfnt) at offset 0x916B 12140 bytes