Malicious PDF — malware analysis report

Static analysis result for SHA-256 3cd4a318575a80b0…

MALICIOUS

PDF

41.7 KB Created: 2020-09-06 14:24:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 81af25d350da68f6ff13a4575e68bfea SHA-1: 5a90eac7802fcb9996a46d577969db85bb97e8e2 SHA-256: 3cd4a318575a80b0c3c8c3d7fb5bc6f76c3f34a11aa13d14da9cde16353356a9
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF file contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.me/wix?keyword=aap+se+milkar+accha+laga+video'. The document body displays the same text, suggesting a social engineering lure to encourage clicking the link. The file also contains a PDF link farm heuristic, indicating a large number of embedded links, many of which point to benign content on static.usrfiles.com, likely to mask the malicious redirector. No scripts were extracted, and the PDF structure itself does not indicate further malicious activity beyond the link redirection.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=aap+se+milkar+accha+laga+video
    • https://static.usrfiles.com/ugd/3826db_54db44b26bb144788a632d055f2bd1ef.pdf
    • https://static.usrfiles.com/ugd/a76634_4ed277cd39d74898afa2231d9267985e.pdf
    • https://static.usrfiles.com/ugd/289c5e_1ae6dfa238314ada856c805c932c5e32.pdf
    • https://cdn.shopify.com/s/files/1/0432/5680/7586/files/abstract_floral_background_vector_free.pdf
    • https://cdn.shopify.com/s/files/1/0459/1216/2453/files/android_auto_full_mirror_without_root.pdf
    • https://cdn.shopify.com/s/files/1/0432/8790/4411/files/97014624948.pdf
    • https://cdn.shopify.com/s/files/1/0432/9809/5272/files/xonafarumirivadif.pdf
    • https://cdn.shopify.com/s/files/1/0435/3576/1576/files/digesuzisirelapusifiwulug.pdf
    • https://cdn.shopify.com/s/files/1/0432/5661/0969/files/nusok.pdf
    • https://cdn.shopify.com/s/files/1/0438/5934/5573/files/77237997600.pdf
    • https://static.usrfiles.com/ugd/a18aa6_7be90373ae0a4fedbd595d0ae31c708a.pdf
    • https://static.usrfiles.com/ugd/b97cba_ffcd7d89ed814c838c0e6a308fe59bb5.pdf
    • https://static.usrfiles.com/ugd/b3bc21_2d42b5148c354f6da97dace56d100f4e.pdf
    • https://static.usrfiles.com/ugd/d99ef3_25230e471d9d446e8eb3ed078f37324f.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005b09.bin
565eea2f790f1a31ca007f7c22f62428956841ccecfd4e8d272eed0d399fcc90
pdf-font-stream PDF embedded font (sfnt) at offset 0x5B09 5600 bytes
font_01_sfnt_off00006df1.bin
0aa510b16be7045ee39b48aff9bac01d1e14da599721cdfa624dcb157306f5db
pdf-font-stream PDF embedded font (sfnt) at offset 0x6DF1 14200 bytes