Malicious PDF — malware analysis report

Static analysis result for SHA-256 959b6a606dd569f7…

MALICIOUS

PDF

46.4 KB Created: 2020-08-29 23:19:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8c56e1cae141769c8f6a31ac28b86a7b SHA-1: 29e3d14bceb17ebd399a512dc2319ef287a9ab5f SHA-256: 959b6a606dd569f7c5b096b046ca3ebb76c366e6ae32ecf8bfff7057f04590bb
128 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious Link T1566.002 Spearphishing Attachment

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/wix?keyword=tempest+addon+download'. Additionally, it exhibits a PDF link farm heuristic, with numerous links hosted on 'static.usrfiles.com'. The document body, though partially garbled, contains text related to 'Tempest addon download' and the authoring application 'wkhtmltopdf', suggesting a lure for a software download. The presence of a visual download button heuristic further supports this. The primary malicious IOC is the redirector URL.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=tempest+addon+download
    • https://static.usrfiles.com/ugd/b8c837_e4166d41eb4c45269922a0a584ee03e0.pdf
    • https://static.usrfiles.com/ugd/b8c837_7a34f25398c34df9b1a99cc4e235aec6.pdf
    • https://static.usrfiles.com/ugd/b8c837_963a1f0ead924d0b943671f60847e9cf.pdf
    • https://static.usrfiles.com/ugd/b8c837_0cbcd5cb10574ca2ac8613995d8126b2.pdf
    • https://static.usrfiles.com/ugd/b8c837_aeba14b6879c43c8a61d852a8f1d1ae3.pdf
    • https://static.usrfiles.com/ugd/b8c837_941cb09722124005a9a745a8750c1b6b.pdf
    • https://static.usrfiles.com/ugd/b8c837_74d288e799504b99958d9226f29c1549.pdf
    • https://static.usrfiles.com/ugd/238140_4fb394c47669441f9c059534ff26604d.pdf
    • https://static.usrfiles.com/ugd/b8c837_21b9ebe27ef7402f87e0d0f199e9f391.pdf
    • https://static.usrfiles.com/ugd/63d3ad_4ce23c760a674f0d87f51b61760a6d81.pdf
    • https://static.usrfiles.com/ugd/b8c837_37cc14b2892646c79dc8fb92c192adb8.pdf
    • https://static.usrfiles.com/ugd/b8c837_10bbf1f3083b4508a2fc06a12fa4fd97.pdf
    • https://static.usrfiles.com/ugd/b8c837_2c1c2a3713ab43eab5e5e0d28b856f2c.pdf
    • https://static.usrfiles.com/ugd/efb3f0_e8fd8ec910064eb79273dbf2d7033248.pdf
    • https://static.usrfiles.com/ugd/b8c837_41e24464f143445f9a2549e235a1821d.pdf
    • https://static.usrfiles.com/ugd/b8c837_c5ccd4701b2d4f4f9a250e922d0e93c1.pdf
    • https://static.usrfiles.com/ugd/b8c837_8afe13fc864541279414b3f8f116622f.pdf
    • https://tempest0580.github.io/
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000078a7.bin
51f39886751d87f7135747f8de26209216387fd8cb5ab5a27854fcd301598e66
pdf-font-stream PDF embedded font (sfnt) at offset 0x78A7 5048 bytes
font_01_sfnt_off000089d3.bin
63114eb335fba6bbfb287e2480df1803d70c482c7dfe78a0cfe1ac793be911fa
pdf-font-stream PDF embedded font (sfnt) at offset 0x89D3 10328 bytes