Malicious PDF — malware analysis report

Static analysis result for SHA-256 4cc4ca329f866c4b…

MALICIOUS

PDF

73.4 KB Created: 2020-08-30 11:03:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 600e8b749a84951ad1eeffb72c696801 SHA-1: 9b6d931e8a93245dbfceb0d3f8a66fe193a08dcb SHA-256: 4cc4ca329f866c4b34989429d1a75913bdf2a68d61285027434e297af4dbac0a
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded external links, many of which point to static.usrfiles.com, suggesting a link farm or SEO manipulation tactic. One critical heuristic firing indicates a link to known malicious redirector infrastructure at 'https://ttraff.link/wix?keyword=sri+sri+mahaprasthanam+telugu+pdf+fr'. The document body, though heavily garbled, contains this same URL, reinforcing its role as the primary lure. No scripts were extracted, and the PDF structure itself does not indicate exploit attempts.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=sri+sri+mahaprasthanam+telugu+pdf+fr
    • https://static.usrfiles.com/ugd/b8c837_cd645dfcb9004143a539970338609758.pdf
    • https://static.usrfiles.com/ugd/5ad03d_b8f616233dce4bf69a451daf94096ffd.pdf
    • https://static.usrfiles.com/ugd/b8c837_0dd76032c2fb4879846c6c50cf3f39df.pdf
    • https://static.usrfiles.com/ugd/b8c837_6a4a28552da14ee794c5e4c0b8485d81.pdf
    • https://static.usrfiles.com/ugd/b8c837_4f0ef534d9c14e938ebf0f527d2bec38.pdf
    • https://static.usrfiles.com/ugd/b8c837_1e6f9280bff74ab08132e5d1f533c3a3.pdf
    • https://static.usrfiles.com/ugd/b8c837_c762cac771034d9f9681d8e751bb0e0c.pdf
    • https://static.usrfiles.com/ugd/b0b521_482c2b3de32942cc8ca5f68cfaa69ad5.pdf
    • https://static.usrfiles.com/ugd/b8c837_ad796a46abf149ef8058e49501923ca8.pdf
    • https://static.usrfiles.com/ugd/b8c837_4d839e889e1743e389a3da0ab895b5a3.pdf
    • https://static.usrfiles.com/ugd/d54300_7d5ad1dbebd74fa8aaa17a1f849532c1.pdf
    • https://static.usrfiles.com/ugd/41a0b6_a330d02e284c4ddd8a2d1609b7b877f7.pdf
    • https://static.usrfiles.com/ugd/c63dba_fc5acb64def540d7b3cf373d9f5f1d88.pdf
    • https://static.usrfiles.com/ugd/227d0f_a93663df95834c91b2ac063e28dd8560.pdf
    • https://static.usrfiles.com/ugd/b8c837_111f842161c24db69370aa173d83e0fb.pdf
    • https://static.usrfiles.com/ugd/b8c837_cec5fffabf6c46e29bee0d0afaadb69c.pdf
    • https://static.usrfiles.com/ugd/b8c837_9ee1c28aca8949a5a4f2c35802287cec.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a8b2.bin
5b4c2e7ae44455f4589d6db0de48133c3aca329611fadf869ad32100e5d16f23
pdf-font-stream PDF embedded font (sfnt) at offset 0xA8B2 5560 bytes
font_01_sfnt_off0000bb67.bin
ff50a402729e2911aea62fe76a90f75b32238a046fc490605c5b3fac679d0550
pdf-font-stream PDF embedded font (sfnt) at offset 0xBB67 28012 bytes
font_02_sfnt_off0000f438.bin
d6f2d0ec6999989ee7f8248dad2010caa33c147cbfb912ba145c56149e90eb83
pdf-font-stream PDF embedded font (sfnt) at offset 0xF438 10540 bytes