Malicious PDF — malware analysis report

Static analysis result for SHA-256 37d5f5929ab08068…

MALICIOUS

PDF

41.5 KB Created: 2020-09-05 20:36:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 0373a0da4be2eb3a6ef20c524749d23e SHA-1: 695b630682835ad153126e4c38eccaa747209576 SHA-256: 37d5f5929ab08068e8bb02725dc9a50985288632fb8224c734c9057d5be933d1
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a link to a known malicious redirector, ttraff.cc, disguised as a legal document template. This suggests a phishing attempt to lure users to malicious infrastructure. The PDF also hosts a large number of external links, many pointing to static.usrfiles.com, which is flagged as a link farm. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=deed+of+appointment+of+trustee+template+nz
    • https://static.usrfiles.com/ugd/bc0d1e_b2c0dfe3be6643e5bd8c0eef670002b9.pdf
    • https://static.usrfiles.com/ugd/d2057d_f6fce7ff966042e0ba8d4688d3ac1fd2.pdf
    • https://static.usrfiles.com/ugd/f3ecbe_7be76fa6a0174bb6995c38e8df98e20a.pdf
    • https://static.usrfiles.com/ugd/2072cd_a1c9ac75e4544b01846ce50d1be27db2.pdf
    • https://static.usrfiles.com/ugd/895bef_9005679cb3e34122927b57cbfc6fd8b5.pdf
    • https://static.usrfiles.com/ugd/384ea4_e50d95b930604458be8018d177cf3358.pdf
    • https://static.usrfiles.com/ugd/1a89c8_3cc04a6edd7e4ca2b2ea7f972900146b.pdf
    • https://static.usrfiles.com/ugd/30e015_59008c2b3ab4419dbdc7797afabe211c.pdf
    • https://static.usrfiles.com/ugd/b8c837_31e591a6907047dc93217a5834b16001.pdf
    • https://static.usrfiles.com/ugd/1e32c2_884f41a5fa4f4aa79951b022eb7a90b7.pdf
    • https://static.usrfiles.com/ugd/99965f_51765db94f324090ab629c446c742e40.pdf
    • https://static.usrfiles.com/ugd/ebc5f9_e082b07ae00840109b453deff927ecb5.pdf
    • https://static.usrfiles.com/ugd/64d889_db7edba39382468d9afed76ede9c385e.pdf
    • https://static.usrfiles.com/ugd/87a178_37ad028b3b5e4e91aacc93cb16dec607.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006137.bin
bfc05478dd5c9e6bff0690277b54d833b9e1e2dd68cb3cdbf7ac0c5e9f1e1d3f
pdf-font-stream PDF embedded font (sfnt) at offset 0x6137 5236 bytes
font_01_sfnt_off00007300.bin
f81bc6c8ea5d9806cd63a188dc76918cf743192d5c98ed9e5afe0a95d58bd6a1
pdf-font-stream PDF embedded font (sfnt) at offset 0x7300 11520 bytes