Malicious PDF — malware analysis report

Static analysis result for SHA-256 a767fb549e34894c…

MALICIOUS

PDF

38.9 KB Created: 2020-09-01 16:00:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6e87a6a1cbb7a40b5dedded52ce580a3 SHA-1: 998ad55daaf444bc30edd0f09e24bc99bb5fe290 SHA-256: a767fb549e34894c169c121ed059c600a5c508afac807a9eb93dcbf394a783d1
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.ru/wix?keyword=bandhan+movie+bhojpuri+video+song'. Additionally, it exhibits characteristics of a PDF link farm, embedding numerous links, with the primary one also leading to the same redirector. The document body, though heavily obfuscated, contains the malicious URL and references to other PDFs hosted on 'static.usrfiles.com', suggesting a lure to download further malicious content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=bandhan+movie+bhojpuri+video+song
    • https://static.usrfiles.com/ugd/eb5a6a_cce35647e24c48d5b27daaf7d05e7825.pdf
    • https://static.usrfiles.com/ugd/04e6f9_3060329163ba4e208cc5604a8b448ba2.pdf
    • https://static.usrfiles.com/ugd/b8c837_86d98b21fc1d43efb53e28b5f3749d7c.pdf
    • https://static.usrfiles.com/ugd/52b593_2d979321f95543939dae4e7f9f2755dc.pdf
    • https://static.usrfiles.com/ugd/df4650_f5180b554c3c4f59aa4ddf68e9dda24f.pdf
    • https://static.usrfiles.com/ugd/a6e5e9_6bb2c5af09c44c5682af9b13db0a416a.pdf
    • https://static.usrfiles.com/ugd/33a16d_013ad8625fe442d2a5dcb955eda269d2.pdf
    • https://static.usrfiles.com/ugd/d78803_6a45d7587773426eb1f384d897d4b094.pdf
    • https://static.usrfiles.com/ugd/b8c837_7201f6fead11433995dd04fb9a5e2270.pdf
    • https://static.usrfiles.com/ugd/be5703_6efc014ea09c476ebfd2eb4707c8403c.pdf
    • https://static.usrfiles.com/ugd/b8c837_50013010c18e477f8e551885bd23c3ea.pdf
    • https://static.usrfiles.com/ugd/66c878_fad9ba435bf246089a9057f54cdb0bf2.pdf
    • https://static.usrfiles.com/ugd/b8c837_077801986ce341a8858c1d3b0c43f43f.pdf
    • https://static.usrfiles.com/ugd/ae15ca_3be895048b4e4096b21422cde202dd6c.pdf
    • https://static.usrfiles.com/ugd/33c377_cbd9f1e43a5e48f6924901cbff7f380c.pdf
    • https://static.usrfiles.com/ugd/865d50_afe468817f304ce8ad28725967d79982.pdf
    • https://static.usrfiles.com/ugd/b8c837_69ebd400c59e461aac51a34e190e0bb3.pdf
    • https://static.usrfiles.com/ugd/1ee69b_595d355b44ad48e4a3b8c2b298b669eb.pdf
    • https://static.usrfiles.com/ugd/5438e3_b79fbb7543954604bbfba0162cf8939f.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000059aa.bin
d4073bc4b3c1bdd04e7378f71ef2573c0e2775588b99a3e1f77c2a2d0a55a246
pdf-font-stream PDF embedded font (sfnt) at offset 0x59AA 5664 bytes
font_01_sfnt_off00006cc7.bin
e665ec694eb4f5a095ad60f467722255807ac4917774ed9706f01442bed08097
pdf-font-stream PDF embedded font (sfnt) at offset 0x6CC7 9772 bytes