Malicious PDF — malware analysis report

Static analysis result for SHA-256 b2768cbf638c17b0…

MALICIOUS

PDF

48.4 KB Created: 2020-09-05 22:48:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 53a32f9d76426124b60da5970bde102a SHA-1: 2905c53dfdfb6505da630e9cca125afbd566b7af SHA-256: b2768cbf638c17b0a2bc82f1281b08ea4d46e1036bcbd2ea1b471d4a8b1b69a5
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a high number of embedded links, many of which point to a link farm hosted on static.usrfiles.com. One critical heuristic identified a link to a known malicious redirector infrastructure at ttraff.club, which is likely the primary malicious payload delivery mechanism. The document body, though heavily obfuscated, contains the URL 'https://ttraff.club/wix?keyword=apple+watch+pride+face', suggesting a lure related to 'apple watch pride face'.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=apple+watch+pride+face
    • https://static.usrfiles.com/ugd/f99735_753ec66e769644b5a37d5d979330132b.pdf
    • https://static.usrfiles.com/ugd/dc98cc_00691b5732114994827d8ba704211fdb.pdf
    • https://static.usrfiles.com/ugd/9eb187_3d15a9bb828e4573956ae80a353a3956.pdf
    • https://static.usrfiles.com/ugd/4dd980_de6f32d92db0414bab5c3e9b6b29cb2f.pdf
    • https://static.usrfiles.com/ugd/55cc32_60106ac72eb34d3789425f913ba00878.pdf
    • https://static.usrfiles.com/ugd/0bcf16_8e99d86689884786812ba4974d8ce0dd.pdf
    • https://static.usrfiles.com/ugd/e4bc37_e765a43458f84893a975838045e94df1.pdf
    • https://static.usrfiles.com/ugd/035627_6e7aa7dd07d24d67bad2abcd0b86386f.pdf
    • https://cdn.shopify.com/s/files/1/0460/0718/9671/files/teri_meri_ankahi_dastan_mp4.pdf
    • https://cdn.shopify.com/s/files/1/0431/7937/6798/files/baxumaxamajure.pdf
    • https://cdn.shopify.com/s/files/1/0434/5944/4896/files/differential_calculus_by_shanti_narayan_download.pdf
    • https://static.usrfiles.com/ugd/0aab01_e74a3a621fff4d3ea6a36d3b40cd8389.pdf
    • https://static.usrfiles.com/ugd/b8c837_a351a8f848b64f968329e47f005afefe.pdf
    • https://static.usrfiles.com/ugd/b8c837_6c465caafb6245ab8528534a815fc2a9.pdf
    • https://static.usrfiles.com/ugd/2813e2_94a83031fd72470daa8363017723d693.pdf
    • https://static.usrfiles.com/ugd/800b88_04dd9a7f69bd4f90ae510c7f31fdeca2.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007284.bin
fd4ea1ff41d23df24c54a42cf14afc7960e361fb53137ea81ec7de68548292e5
pdf-font-stream PDF embedded font (sfnt) at offset 0x7284 4716 bytes
font_01_sfnt_off000082a9.bin
8d2d23fc0147d1c481ae27270bf267638b27b93d153202a893042cef4e6665bc
pdf-font-stream PDF embedded font (sfnt) at offset 0x82A9 10520 bytes
font_02_sfnt_off0000a692.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0xA692 4324 bytes