Malicious PDF — malware analysis report

Static analysis result for SHA-256 2de147ac36d9fd42…

MALICIOUS

PDF

63.1 KB Created: 2020-08-29 02:06:44 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 479d832e471008f83725014c63ae3158 SHA-1: 337ebba2bc4ec40d277514a0b2f304aecbc34bcd SHA-256: 2de147ac36d9fd4278683595b128803baeb5ce8cdcecd7e60885f7c60fda5db8
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing for a malicious redirector link, pointing to a URL that appears to be part of an SEO link farm. The document body, though heavily obfuscated, contains the same URL and a reference to a PDF file hosted on static.usrfiles.com, suggesting a lure to a malicious site. The primary malicious URL is https://ttraff.ru/wix?keyword=harry+potter+theme+song+jarrod+radni.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=harry+potter+theme+song+jarrod+radni
    • https://static.usrfiles.com/ugd/b8c837_c9284648f0674d97873414254bab00d0.pdf
    • https://static.usrfiles.com/ugd/b8c837_eb565f218451427fb885b22ba80aca81.pdf
    • https://static.usrfiles.com/ugd/b8c837_e11ca8e0172f4fe2b578c08cd5c2c96b.pdf
    • https://static.usrfiles.com/ugd/b8c837_08c399fe49304148b41c4bf101ebb749.pdf
    • https://cdn.shopify.com/s/files/1/0431/8255/5297/files/40440057377.pdf
    • https://cdn.shopify.com/s/files/1/0431/4749/3536/files/majire.pdf
    • https://cdn.shopify.com/s/files/1/0429/9869/4049/files/85186553668.pdf
    • https://cdn.shopify.com/s/files/1/0432/1535/6067/files/75436688575.pdf
    • https://cdn.shopify.com/s/files/1/0431/1125/2132/files/lovipil.pdf
    • https://static.usrfiles.com/ugd/b8c837_b880260303124c3ebfbdd386b1fb8ee4.pdf
    • https://static.usrfiles.com/ugd/b8c837_51dff2fc513d4c2ba5afc9482df72f35.pdf
    • https://static.usrfiles.com/ugd/b8c837_570843dfa00848aa8f001642ff081495.pdf
    • https://static.usrfiles.com/ugd/b8c837_c69bbc6839a4483286f90113381a2ba4.pdf
    • https://static.usrfiles.com/ugd/b8c837_6eb4a8b1930d423eb87b3e8f3afcc765.pdf
    • https://static.usrfiles.com/ugd/b8c837_1bf73c9469a149e29844297101e16ec4.pdf
    • https://static.usrfiles.com/ugd/b8c837_c9ba99c7a4b24ae69c9c8d3a7931dd0b.pdf
    • https://static.usrfiles.com/ugd/b8c837_8c8db09b874642879def5dcbfd0058e2.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007944.bin
fa72874b8c381873b432d3b5cea9ecddba20f04e8e1c9face7d560df1136061a
pdf-font-stream PDF embedded font (sfnt) at offset 0x7944 6588 bytes
font_01_sfnt_off000089be.bin
9c9dc140b6be1473125cd07ed119741d659ea817b7a72140baeb900f55967232
pdf-font-stream PDF embedded font (sfnt) at offset 0x89BE 5480 bytes
font_02_sfnt_off00009c3f.bin
f63a98669466ff1c8f1e8ec8284b1835b25fd9dc840fe9c248f18b731b5f997e
pdf-font-stream PDF embedded font (sfnt) at offset 0x9C3F 6036 bytes
font_03_sfnt_off0000b1f0.bin
2a2392a77b4b2c1aef3179f29651d0c2f4b03e4aa399fdddcf85c0a913b26735
pdf-font-stream PDF embedded font (sfnt) at offset 0xB1F0 10472 bytes
font_04_sfnt_off0000d600.bin
52a0b31aaffc817f0ded7b3a840f67698454443ccae658a73ccd618395c8488a
pdf-font-stream PDF embedded font (sfnt) at offset 0xD600 17048 bytes