Malicious PDF — malware analysis report

Static analysis result for SHA-256 7da5783a55e03bce…

MALICIOUS

PDF

44.3 KB Created: 2020-08-31 05:04:48 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c0032d8fd1b98c21fde470a8e4f01271 SHA-1: 1f2373ce150d6a8f54d67fc6dc3bd0d00263159e SHA-256: 7da5783a55e03bce11a565ed323e6c2de685dcef72dece6d04de0b99cb9c30f4
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a link to a known malicious redirector, ttraff.com, which is disguised as a download link for '3d movies gear vr'. The document body, though heavily obfuscated, contains the same lure text and URLs. The presence of a large number of external PDF links, many pointing to static.usrfiles.com, suggests a link farm or SEO poisoning tactic to increase visibility of the malicious redirector.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=download+3d+movies+gear+vr
    • https://static.usrfiles.com/ugd/b8c837_86c9a4350dd940938455b2054075c08f.pdf
    • https://static.usrfiles.com/ugd/6cf392_9af3db97fd4e4e4eb23d4db6b905a327.pdf
    • https://static.usrfiles.com/ugd/b8c837_00f12b5f256a46199567452546e0d61c.pdf
    • https://static.usrfiles.com/ugd/b8c837_50bab3f08c394066abee1ec8615017ce.pdf
    • https://static.usrfiles.com/ugd/5ecadc_4a327d25c03b4ae6ae327d30a736449d.pdf
    • https://static.usrfiles.com/ugd/de60da_25919486669346f192817bce97e63b3a.pdf
    • https://static.usrfiles.com/ugd/b8c837_dad603711759498baecad27aba6bcb64.pdf
    • https://static.usrfiles.com/ugd/b8c837_d4596a7deb9a4e2b80d4de45785102e6.pdf
    • https://static.usrfiles.com/ugd/b8c837_034fe068f00c4feab4e6424493976977.pdf
    • https://static.usrfiles.com/ugd/71fd01_4b2503d48a6349cab06f33909ff514c2.pdf
    • https://static.usrfiles.com/ugd/b8c837_fb535a3769be4c5fbdc1600a9f909bca.pdf
    • https://static.usrfiles.com/ugd/b5aed9_ec97888ecc4449598d6df6c06280b39c.pdf
    • https://static.usrfiles.com/ugd/4b7290_9cbbb6ff0f9c4d8fb539c22af86c6759.pdf
    • https://static.usrfiles.com/ugd/b5472a_37455df8540e4ad78998cd48527bfcec.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000060ac.bin
1815ac4d104f8054845b09b10d1d01d32e57a78bdd2a948b051a1e9322de2620
pdf-font-stream PDF embedded font (sfnt) at offset 0x60AC 5168 bytes
font_01_sfnt_off00007230.bin
32a41bb34bd0c2ca1776bdb170b2cc8969d0c1bd0a276c2529f71a65b9fee790
pdf-font-stream PDF embedded font (sfnt) at offset 0x7230 10752 bytes
font_02_sfnt_off0000966a.bin
9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x966A 4324 bytes