Malicious PDF — malware analysis report

Static analysis result for SHA-256 310c5bc324a863c9…

MALICIOUS

PDF

36.9 KB Created: 2020-09-07 14:32:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8a2abe40a7d6d16a72e2557c83df01d7 SHA-1: 664c4eb9cd1fd73d7ea46534aacf03395969d9d2 SHA-256: 310c5bc324a863c9a5a8e2efeb95519e785ce80bf1aaf603251a091d50575ff9
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

This PDF document contains a link to a known malicious redirector, ttraff.link, which is designed to lead users to malicious content. The document body, though heavily obfuscated, contains the same URL and appears to be a lure related to 'Twitter for blackberry z10'. The presence of a link farm further suggests a malicious intent to distribute links to potentially harmful content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=twitter+for+blackberry+z10
    • https://static.usrfiles.com/ugd/a2e20a_714bfec2791e4260abe410771c2fc1af.pdf
    • https://static.usrfiles.com/ugd/b8c837_1ee47d256e764390bb80a568278c3939.pdf
    • https://static.usrfiles.com/ugd/5fd5c1_58a7dcdbe910404e906eeb67b11bdfd8.pdf
    • https://static.usrfiles.com/ugd/67f5f7_a7500f1d07f642ac8f3e9a493a22c389.pdf
    • https://static.usrfiles.com/ugd/b8c837_b04b151de58545ecbe6dbab3f5d30991.pdf
    • https://static.usrfiles.com/ugd/2486b5_89c9e88cdc6642dca16f983c5746b30d.pdf
    • https://static.usrfiles.com/ugd/3d514e_b7260db8f2594170b25cb1775477acb4.pdf
    • https://static.usrfiles.com/ugd/0c8cc8_4a3695ba8a7546369328ac5f3a97c98c.pdf
    • https://static.usrfiles.com/ugd/73cb9e_145ac555477f46a887ed9cc8fe59c102.pdf
    • https://static.usrfiles.com/ugd/f523c3_9545c5512f934f6c89b03c465c24fefa.pdf
    • https://cdn.shopify.com/s/files/1/0432/2027/1264/files/lukonemebaketori.pdf
    • https://cdn.shopify.com/s/files/1/0433/7657/4620/files/74104039107.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000051a9.bin
948a3e5f5c0ce4c8f614dc064a31e49deac75f9b36d494b185c3be78e30572e7
pdf-font-stream PDF embedded font (sfnt) at offset 0x51A9 5288 bytes
font_01_sfnt_off000063de.bin
49040fecb24aade6223c75caf8c775aebff200cae7121e9e35af5c31b607d15c
pdf-font-stream PDF embedded font (sfnt) at offset 0x63DE 10272 bytes