Malicious PDF — malware analysis report

Static analysis result for SHA-256 99913806021ab972…

MALICIOUS

PDF

33.6 KB Created: 2020-09-01 04:43:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9fb79514182eec46e0d230ea403b0033 SHA-1: 08133d50731e78bdcb60f731904d644a265ef075 SHA-256: 99913806021ab97291d9bc43479a3f93b73cb6b16a879be6bc007ad5b70a89cf
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a malicious redirector link that points to ttraff.com, which is flagged as malicious. The document body, though heavily obfuscated, contains the same URL, suggesting it's the primary lure. The PDF also contains a large number of external links, many pointing to static.usrfiles.com, which is identified as a link farm. The ML classifier strongly indicates maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=huawei+60+kw+inverter+datasheet
    • https://static.usrfiles.com/ugd/f63f29_7919feddcdfa4282a9454db8474df2eb.pdf
    • https://static.usrfiles.com/ugd/a58b01_a019b85985dc434caebe4ff579d980ef.pdf
    • https://static.usrfiles.com/ugd/b8c837_5b60b0c50f844d458b006f84c3d5d206.pdf
    • https://static.usrfiles.com/ugd/b8c837_65e00add5f7e4f819b732a07367ea238.pdf
    • https://static.usrfiles.com/ugd/f46427_56314b1286a946c38e7ff23fc3d96cc2.pdf
    • https://static.usrfiles.com/ugd/33ab24_156059ea07ea40f9b11d9cd336d9473f.pdf
    • https://static.usrfiles.com/ugd/1cc777_72d0b3131b3748539ce9aff92392786e.pdf
    • https://static.usrfiles.com/ugd/76156b_25676c1fc8324fbf8e4558a047313912.pdf
    • https://static.usrfiles.com/ugd/dba42a_ea5bfcf138254d168e39d8872578450c.pdf
    • https://static.usrfiles.com/ugd/f0e51d_1ea8ddef8ab44378be13060120f5ff5e.pdf
    • https://static.usrfiles.com/ugd/67e251_1fb50ed9d47b42be8de4794d0fa99964.pdf
    • https://static.usrfiles.com/ugd/ab922d_6f318bbfe8af4ca9bd28871063187cc1.pdf
    • https://static.usrfiles.com/ugd/54fa57_2e70d80e40864535b50287a8e0039527.pdf
    • https://static.usrfiles.com/ugd/7e0eb0_54557d9c121645759b8df826538e157c.pdf
    • https://static.usrfiles.com/ugd/b8c837_a96e8acb28fd41e1b6dbd50369af9295.pdf
    • https://static.usrfiles.com/ugd/b8c837_67710c0cfd694f7d96f786230b9ed7a9.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004525.bin
ceee42eae96eaca61f8651550884988b6f06b444315cdf27a68a032b6ca340f2
pdf-font-stream PDF embedded font (sfnt) at offset 0x4525 5356 bytes
font_01_sfnt_off00005768.bin
b4f73108f8f46dfd4515d84e1dcf21fc8a7ed8ea6b232b723426cd03ceb3fefb
pdf-font-stream PDF embedded font (sfnt) at offset 0x5768 9980 bytes