Malicious PDF — malware analysis report

Static analysis result for SHA-256 8c3b583f06e51c9f…

MALICIOUS

PDF

39.4 KB Created: 2020-09-17 05:31:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6ac90d2bf0f9c6927692857620371471 SHA-1: 9a32c9f0b932088ea641b9ddbfaf848f184fc0c7 SHA-256: 8c3b583f06e51c9f3ad2f1788e48fbe9fea804e8b353409b67585e60deab33d8
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, many of which point to external resources. One prominent link, 'https://ttraff.club/wix?keyword=horses+in+the+back+remix+roblox+id', is identified as a malicious redirector. The document body, though heavily obfuscated, contains references to this URL and other PDF files, suggesting a link farm or redirection strategy. The presence of numerous links and the identified malicious redirector indicate an attempt to lead the user to harmful content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=horses+in+the+back+remix+roblox+id
    • http://files.ginquistphotography.com/uploads/1/3/1/4/131406563/4246713.pdf
    • http://files.debarkeddesigns.com/uploads/1/3/1/3/131384721/9b2d6b649.pdf
    • http://files.sirkil.com/uploads/1/3/1/4/131454034/9ba47808dc3f3a.pdf
    • https://784e1254-343c-436b-a9e1-80bc7e16b1b6.filesusr.com/ugd/c88839_260a1bc65bd641108e681571b6a80b32.pdf?index=true
    • https://1ae716e7-0117-4f73-8327-a2b8baeacdf6.filesusr.com/ugd/2994dd_c1ea7d459158410b948bd86e11089f58.pdf?index=true
    • https://765aef3a-5fda-4d6b-8bb7-549f4895eb90.filesusr.com/ugd/7598fa_214e4dd14c2347edbadf54b8faeb20f2.pdf?index=true
    • https://99c6f765-dbb0-4dd9-bb66-4bbc49d74c12.filesusr.com/ugd/067ecb_91e00a4c70f84b189b0ca12ce7bd635e.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0433/5370/2550/files/29247393203.pdf
    • https://cdn.shopify.com/s/files/1/0456/4549/6487/files/rustoleum_spray_paint_safety_data_sheet.pdf
    • https://cdn.shopify.com/s/files/1/0430/9562/1781/files/alcatel_u5_instruction_manual.pdf
    • https://cdn.shopify.com/s/files/1/0437/0399/2485/files/fishing_report_central_oregon.pdf
    • https://cdn.shopify.com/s/files/1/0436/5395/5742/files/que_es_nivelacion_barometrica.pdf
    • https://cdn.shopify.com/s/files/1/0432/5844/5979/files/17418361838.pdf
    • https://cdn.shopify.com/s/files/1/0450/2038/1342/files/a_journey_through_anglo_american_literature_learner_s_material.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/92835403356.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005054.bin
38c75a0a32a113e47338e006940eae33b91883add63d88d969dbab71d3addd67
pdf-font-stream PDF embedded font (sfnt) at offset 0x5054 5412 bytes
font_01_sfnt_off00006289.bin
8b74c108a531e31ad141b3c402ad807dd98bb0ab2069d8e881bcdec93ccd3c7e
pdf-font-stream PDF embedded font (sfnt) at offset 0x6289 14192 bytes