Malicious PDF — malware analysis report

Static analysis result for SHA-256 3f158e6d00ca47b2…

MALICIOUS

PDF

54.2 KB Created: 2020-08-29 16:48:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bb1aafc597a7a68b0d052a50a988b259 SHA-1: 2fdf0b8eb91ded86a3a4135b963e2d2a3783335a SHA-256: 3f158e6d00ca47b2f69344067b29045c486f9c0a37b87c15c6214de8bdf0d9b3
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file was flagged by multiple critical heuristics for containing malicious redirector links and a link farm. The embedded URL 'https://ttraff.ru/wix?keyword=ouke+no+monshou+scan' is a primary indicator of malicious intent. The document body, though heavily obfuscated, also contains this URL, suggesting it is central to the lure. The presence of numerous links to static.usrfiles.com, even if some are benign, contributes to the overall link farm characteristic.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=ouke+no+monshou+scan
    • https://static.usrfiles.com/ugd/b8c837_bde90f7483ef46718d6fc682b1c3613f.pdf
    • https://static.usrfiles.com/ugd/b98abb_d79e242c3f5a4db4a2d01d203a970ed8.pdf
    • https://static.usrfiles.com/ugd/b8c837_95d3cb5d56764b24be6e54d0e39ab094.pdf
    • https://static.usrfiles.com/ugd/b8c837_2221e226f0e647fa94630d322fa78eca.pdf
    • https://static.usrfiles.com/ugd/b8c837_7fdb069ff4f04dcbb37ab1446f3308e2.pdf
    • https://static.usrfiles.com/ugd/a76634_1e952ce78c27431cb0b8109d37decb24.pdf
    • https://static.usrfiles.com/ugd/3f80ec_dd1af3bd92bc4ca69baa877c13c85fd9.pdf
    • https://static.usrfiles.com/ugd/b8c837_e51eb82ffb154d6ea71517379899237c.pdf
    • https://static.usrfiles.com/ugd/0d002d_bc8af9b18fad4b7ab6f62c5953c23a27.pdf
    • https://static.usrfiles.com/ugd/b8c837_38d614b8dec34dcc881415fb9c583ce8.pdf
    • https://static.usrfiles.com/ugd/b8c837_54e8b102048c4dca9b8bdb9a244ef5ac.pdf
    • https://static.usrfiles.com/ugd/b8c837_fa1ed2993df2487d960fe704b1703569.pdf
    • https://static.usrfiles.com/ugd/80c1db_b408f26d40cc44b39482cfcc89aff5a1.pdf
    • https://static.usrfiles.com/ugd/b8c837_eb2cca3328cd466c88673fc95aa4b9cb.pdf
    • https://static.usrfiles.com/ugd/b8c837_1b2ea211f6774780906f6e8b7e9151f7.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005a92.bin
0d4f8cf2cc509cca77a5a6f980d317ca092e76e42f414c455f1934b8d17e5b4a
pdf-font-stream PDF embedded font (sfnt) at offset 0x5A92 5708 bytes
font_01_sfnt_off00006e7c.bin
1505b6bcede7fb4fcbbcfe1f05f12b96365e518480a450aa6103c9bd97e5d31a
pdf-font-stream PDF embedded font (sfnt) at offset 0x6E7C 4756 bytes
font_02_sfnt_off00007e63.bin
e994a6ecb1b4c0b989746232a10f07d28cbb7e2afbeefd731c2ba21ef350bc58
pdf-font-stream PDF embedded font (sfnt) at offset 0x7E63 7152 bytes
font_03_sfnt_off0000919d.bin
5dfc7f7b8dda0c3784b93d60e316570a5dd2b3a46b2b5753918f265f7a020cc4
pdf-font-stream PDF embedded font (sfnt) at offset 0x919D 14028 bytes
font_04_sfnt_off0000bcfc.bin
cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34
pdf-font-stream PDF embedded font (sfnt) at offset 0xBCFC 4324 bytes