Malicious PDF — malware analysis report

Static analysis result for SHA-256 578090eacd2bfea2…

MALICIOUS

PDF

76.3 KB Created: 2020-08-30 04:08:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 81e79238f5dc0f25b18d9905b61744c1 SHA-1: 7bed30e963516a6ab184c2fb98478589f3d286ab SHA-256: 578090eacd2bfea277d0a2d38b832b337534a1e44a8b5b06089a1ad46885585a
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.001 Malicious Link T1059.001 PowerShell

The PDF contains a heuristic firing for a malicious redirector link pointing to 'https://ttraff.com/wix?keyword=que+es+ritmica+musical'. Additionally, it exhibits characteristics of a PDF link farm, with numerous external links, one of which is 'https://static.usrfiles.com/ugd/b56239_95149ec1a22d4477803c5ee07ab25303.pdf'. The document body, though heavily obfuscated, contains the same URL, suggesting it's the primary lure. The presence of these elements indicates a likely phishing or malware distribution attempt.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=que+es+ritmica+musical
    • https://static.usrfiles.com/ugd/b56239_95149ec1a22d4477803c5ee07ab25303.pdf
    • https://static.usrfiles.com/ugd/b8c837_2e20cf22dcff4ccd9db6f99ace2f907b.pdf
    • https://static.usrfiles.com/ugd/b8c837_3e01101c276c4def90c95f0ac247a265.pdf
    • https://static.usrfiles.com/ugd/b58d21_6e0c0a438d9844c1b2cc9f340feca97a.pdf
    • https://static.usrfiles.com/ugd/07625c_73d7ac64ee9f46b0b1165be7127193a7.pdf
    • https://static.usrfiles.com/ugd/b8c837_56a55d44d62a4731ad5ed01b4f256b52.pdf
    • https://static.usrfiles.com/ugd/b444d4_a7a5d29ee2e64f2aaa1cd7408edd4bca.pdf
    • https://static.usrfiles.com/ugd/b8c837_71abadd34b074b6fbf1a82c59012821b.pdf
    • https://static.usrfiles.com/ugd/b8c837_9b379de2e3ad4784b77d7e57621d9fbe.pdf
    • https://cdn.shopify.com/s/files/1/0428/6332/9446/files/pexaxuwexamupogikifoj.pdf
    • https://cdn.shopify.com/s/files/1/0429/2358/9788/files/lamoxebipalenexo.pdf
    • https://cdn.shopify.com/s/files/1/0432/9832/4638/files/28160791014.pdf
    • https://cdn.shopify.com/s/files/1/0428/2246/7740/files/36232353949.pdf
    • https://cdn.shopify.com/s/files/1/0427/7148/0742/files/pokerenopenuvel.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e9ae.bin
5c97043cfda8f25f34bd3509181d79dabdbbedf78b49fd605c6374cc2e929d89
pdf-font-stream PDF embedded font (sfnt) at offset 0xE9AE 5008 bytes
font_01_sfnt_off0000fa98.bin
1468df088edb542db60266d78c1f9c7b20013f6411b67aaca98c8580349d3d2f
pdf-font-stream PDF embedded font (sfnt) at offset 0xFA98 12344 bytes