Malicious PDF — malware analysis report

Static analysis result for SHA-256 2856a8386967f3a4…

MALICIOUS

PDF

50.4 KB Created: 2020-08-31 05:41:43 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 98c01f27192d97d79b485d933b68f45f SHA-1: d9e33a1a0b73f318575983eb37e79e5186ffcee1 SHA-256: 2856a8386967f3a427404926197a50159efdd26417e2f99b50c03d4a10aff52c
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a link to a known malicious redirector, ttraff.cc, which is disguised with a keyword related to the game Warframe. This suggests a phishing or scam attempt to lure users to malicious content. The PDF also contains a large number of external links, many of which point to benign content, but the primary malicious link is the most concerning IOC. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=warframe+weapon+ingredients
    • https://static.usrfiles.com/ugd/b8c837_99c046e40dcc4af7983cd09e6ce7d7d5.pdf
    • https://static.usrfiles.com/ugd/4cf28d_91bca289dbc64063a0b21aca368bed44.pdf
    • https://static.usrfiles.com/ugd/5bb01c_5975e8a292ed437fafc6484cd5dcf53d.pdf
    • https://static.usrfiles.com/ugd/0a0016_8f44cfc49f8c4fb2ae1474cda3eb9387.pdf
    • https://static.usrfiles.com/ugd/defcb2_32f0cc0410ec4c4f89e8a3d53a0ea6cb.pdf
    • https://static.usrfiles.com/ugd/f55bec_d152f04e8d6b4a3aa44bce5b9107b88b.pdf
    • https://static.usrfiles.com/ugd/b8c837_275931a6218d46978e50a8921bcc6fe1.pdf
    • https://static.usrfiles.com/ugd/b8c837_5b43aa52fe5544a390e22e3d4a170f3b.pdf
    • https://static.usrfiles.com/ugd/b8c837_f233452c5c7f4ad3997400f5b8f625a5.pdf
    • https://static.usrfiles.com/ugd/cafc24_02d635edc38e4bd997737b52f9860fba.pdf
    • https://static.usrfiles.com/ugd/d5cf39_80a6d89b9fa04097828cf2bc4941a6b5.pdf
    • https://static.usrfiles.com/ugd/48d9a1_aed732f77ae049ce992cb4b7d8ab9148.pdf
    • https://static.usrfiles.com/ugd/429b25_d1b44780b8c1420fb867f650a2da1d8f.pdf
    • https://static.usrfiles.com/ugd/b8c837_8d131643174e403598696e0872934691.pdf
    • https://static.usrfiles.com/ugd/b8c837_61f9a956a804494d9c3f16d03c9cedbb.pdf
    • https://static.usrfiles.com/ugd/b8c837_0252aac7b25f41178d4ae09497bf6393.pdf
    • https://static.usrfiles.com/ugd/6cf392_5ddae702e28a4e3882de0fa84c2f73f3.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000067c8.bin
3b6fd54ade763ed3f24cbba9fd3f6ee7124eeb45bf86cb5947a4562d0fe5caa2
pdf-font-stream PDF embedded font (sfnt) at offset 0x67C8 5432 bytes
font_01_sfnt_off00007a42.bin
f531b4155818364ef4a088ed0dd27d548027d5f037f0ada69f799000b94fb6cd
pdf-font-stream PDF embedded font (sfnt) at offset 0x7A42 11724 bytes
font_02_sfnt_off00009f8b.bin
b666b94ab3054a80e377a141d35d7530cc05ea895ac1e4dcf42ae39ad0706483
pdf-font-stream PDF embedded font (sfnt) at offset 0x9F8B 18372 bytes