Malicious PDF — malware analysis report

Static analysis result for SHA-256 2b8418d0db2a350c…

MALICIOUS

PDF

43.6 KB Created: 2020-09-05 08:17:14 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0155113331b5b3c6d96158430157a779 SHA-1: 5f0c2bae878d174378984de36c2bd8bdc9f1fc94 SHA-256: 2b8418d0db2a350c38121990c039bcf7d7a81e4d7156a0d254b933e028fa2b6e
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.me/wix?keyword=laplace+m+guide+job'. The document body, though heavily garbled, contains this URL and appears to be a lure related to a 'guide job'. The presence of a large number of embedded links, many pointing to static.usrfiles.com, suggests a link farm designed to attract traffic, with the primary malicious redirector being the most critical IOC.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=laplace+m+guide+job
    • https://static.usrfiles.com/ugd/f8de3e_5c4c93be484143d8b10f11d52c36efd4.pdf
    • https://static.usrfiles.com/ugd/de65f7_75cefc5059fb44318b9662fa99d8c6b8.pdf
    • https://static.usrfiles.com/ugd/312e0e_5a06a5a87c834a7eb6edcd689cd01053.pdf
    • https://static.usrfiles.com/ugd/6f7357_318931adf7c54d8286e8475ad729a4e6.pdf
    • https://static.usrfiles.com/ugd/b8c837_41b445d729604eb491da607c374981f2.pdf
    • https://static.usrfiles.com/ugd/191a6d_2c21950701184204b8c321affadea746.pdf
    • https://static.usrfiles.com/ugd/9904c2_acd739548ee14540902c022fe46ea03f.pdf
    • https://static.usrfiles.com/ugd/7d2910_303f416fcf2046bda85013cc153f5a24.pdf
    • https://static.usrfiles.com/ugd/b8c837_7a48f3dce772440195f05f96363dcfef.pdf
    • https://static.usrfiles.com/ugd/429b25_5b591e69515a489baade165d99228b33.pdf
    • https://static.usrfiles.com/ugd/d1d005_de12ed29f5b34ccea0e1d0ca7f71d5f3.pdf
    • https://static.usrfiles.com/ugd/8ab72e_5b8f3684aa814efbadbe48955e4df3ff.pdf
    • https://static.usrfiles.com/ugd/0c41e7_e3d8bd40624143c3ad1139cd5e4bc667.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006d32.bin
3645060c5057bc110ea9aac7bdd891fa80ccaa387f423f51b8efb347aa3a7b94
pdf-font-stream PDF embedded font (sfnt) at offset 0x6D32 5276 bytes
font_01_sfnt_off00007f15.bin
e958e388226e58a00ff97ce2f7712db9e1e467269bec1fa0acdc0ceae88a2348
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F15 10268 bytes