Malicious PDF — malware analysis report

Static analysis result for SHA-256 b1c7dd4bfa8920b2…

MALICIOUS

PDF

43.3 KB Created: 2020-08-30 18:25:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2eac9643db7e684cd8b9518cbd3e3910 SHA-1: 9b3c6f19255591f1d8c33be26ce09972217d791f SHA-256: b1c7dd4bfa8920b2ab3dcd07009fd35a917ccd7831c01671cfd1ca30cab9c03e
142 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a link to a known malicious redirector, ttraff.ru, which is likely used to funnel victims to further malicious content. Additionally, the PDF exhibits characteristics of a link farm, containing numerous links to external PDFs hosted on static.usrfiles.com. The document body, though heavily obfuscated, contains the URL that triggered the malicious redirector heuristic. The presence of multiple external links suggests an attempt to broaden the attack surface or distribute payloads through various means.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=csumb+student+orientation
    • https://static.usrfiles.com/ugd/b8c837_ef403b0c606d477e9fae24e17ab10a88.pdf
    • https://static.usrfiles.com/ugd/76156b_045183bceaf74cf68dffff3fc6ce4cb6.pdf
    • https://static.usrfiles.com/ugd/ab922d_18cc36b6179841e3b46396bb6dea2710.pdf
    • https://static.usrfiles.com/ugd/1be480_189479bb34a64633a2b7310aba31d95a.pdf
    • https://static.usrfiles.com/ugd/eaf48f_8571dcf91457474c8fc9625a4d0db10c.pdf
    • https://static.usrfiles.com/ugd/b8c837_64069673e5bd42459bcd90bf7354534d.pdf
    • https://static.usrfiles.com/ugd/c0b427_13e01142e8b442339fac132dee5278e2.pdf
    • https://static.usrfiles.com/ugd/b8c837_b2cef5258e2f4b43b3ac8039376843e3.pdf
    • https://static.usrfiles.com/ugd/1e4819_b953068543674fbabe66cc3d0b8e71f1.pdf
    • https://static.usrfiles.com/ugd/b8c837_935f39ae9fc64dfdafd45904ef9bd08c.pdf
    • https://static.usrfiles.com/ugd/dad90e_6310590e936e4814b617fa87c100c746.pdf
    • https://static.usrfiles.com/ugd/fb5067_85ef4cb8f40b4e668680c08e0ecb9728.pdf
    • https://cdn.shopify.com/s/files/1/0429/7618/2426/files/vizelilelupujonojokix.pdf
    • https://cdn.shopify.com/s/files/1/0427/5198/3783/files/6966130041.pdf
    • https://cdn.shopify.com/s/files/1/0432/0552/5661/files/19025692161.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/11383010616.pdf
    • https://cdn.shopify.com/s/files/1/0457/7525/7756/files/chess_for_windows_8._1.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006b45.bin
d8adab1d5704d25fe26342c7621482f46f2d4251b82f59465cdfd3fef20c85c5
pdf-font-stream PDF embedded font (sfnt) at offset 0x6B45 4984 bytes
font_01_sfnt_off00007c0e.bin
9b96b7ba99a81a04e404492592c08841540c2a898115a43afa49e982d78fdb2a
pdf-font-stream PDF embedded font (sfnt) at offset 0x7C0E 10588 bytes