Malicious PDF — malware analysis report

Static analysis result for SHA-256 a0d0b336a8f68b5b…

MALICIOUS

PDF

42.7 KB Created: 2020-08-31 07:03:06 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 88bf8fc956ddbafc724aaa5aa3edc059 SHA-1: 50b65bb8d8abcc5ce8bee59a1cd08b2dca14925e SHA-256: a0d0b336a8f68b5b1c0003c2cf261f8fe13d7d42eff87cb4e8a9091c70b2b353
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link pointing to 'ttraff.com'. Additionally, it exhibits characteristics of a link farm, embedding numerous external PDF links, many hosted on 'static.usrfiles.com'. The document body, though heavily obfuscated, contains the URL 'https://ttraff.com/wix?keyword=the+forest+building+guide', suggesting a lure to a malicious site disguised as a guide.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=the+forest+building+guide
    • https://static.usrfiles.com/ugd/b65acf_89470952a4b642c5ae0bc6c351ecac23.pdf
    • https://static.usrfiles.com/ugd/b8c837_23559e27f8854df29882598d845599b0.pdf
    • https://static.usrfiles.com/ugd/0baf77_925342ab5f6a4b5aae539987fef92ba0.pdf
    • https://static.usrfiles.com/ugd/b8c837_f66acebd9c5a44d2b41c188da780c883.pdf
    • https://cdn.shopify.com/s/files/1/0438/0108/4064/files/apology_letter_for_reporting_late_to_work.pdf
    • https://static.usrfiles.com/ugd/b8c837_b22f59b59907468798f4fda32dbf3f5f.pdf
    • https://static.usrfiles.com/ugd/b8c837_441e3a808b99455dab9bd83af84f3a4f.pdf
    • https://static.usrfiles.com/ugd/b8c837_587e896de49d4d42a7a8fb22847c1373.pdf
    • https://cdn.shopify.com/s/files/1/0428/3059/4204/files/26150460667.pdf
    • https://cdn.shopify.com/s/files/1/0439/7904/7070/files/the_technical_analysis_course_4th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0439/2094/9416/files/84452263134.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006b29.bin
baa95add6b1aa51d44d1fbb7ca651d6199b3e041f2f43ef51ff5e159b7758839
pdf-font-stream PDF embedded font (sfnt) at offset 0x6B29 5048 bytes
font_01_sfnt_off00007c4e.bin
bef7ab18edfe516fcf419dcb8dfaf5415fd8581a897e35bdeb5dc9b6d3781828
pdf-font-stream PDF embedded font (sfnt) at offset 0x7C4E 9980 bytes