Malicious PDF — malware analysis report

Static analysis result for SHA-256 b4fb6e97a77096bb…

MALICIOUS

PDF

73.8 KB Created: 2020-09-01 13:53:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 64f67673d7ae97ed0a08f5ca86cef9bf SHA-1: 77308c5dbec2f8f8a188d2d3e95863b7af3cd7b5 SHA-256: b4fb6e97a77096bbf5db922561513cd86bc774a57e4a040b7a319d6705803337
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a lure for fake invoices or payments, as indicated by the SE_INVOICE_LURE heuristic. It embeds a link to a malicious redirector, ttraff.link, which is designed to lead users to further malicious content. The PDF also contains a large number of external links, many pointing to static.usrfiles.com, suggesting a link farm or SEO poisoning tactic to improve search engine ranking for malicious content. No scripts were extracted from this sample.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/wix?keyword=suits+season+9+episode+7+subtitles
    • https://static.usrfiles.com/ugd/32acb1_eb9c9bbb0efd468eacab3f62b1d4fe60.pdf
    • https://static.usrfiles.com/ugd/e1d12c_328a3c62061c4a45907c1f3b1dc4e72e.pdf
    • https://static.usrfiles.com/ugd/3649d2_2e222c9315e244af80152fbc09d77bd7.pdf
    • https://static.usrfiles.com/ugd/314c35_6315f15dcec343ee96b8974dd1b173db.pdf
    • https://static.usrfiles.com/ugd/0d002d_5651531bea754ae5b8c92f6ae3caa87f.pdf
    • https://static.usrfiles.com/ugd/704566_9ef4a822e87543adbd7cc0cadddb034c.pdf
    • https://static.usrfiles.com/ugd/b8c837_e675a2250c904eb7b62ac519e0869a72.pdf
    • https://static.usrfiles.com/ugd/fd7405_4c89665664fd471bae1fb15cb627c626.pdf
    • https://static.usrfiles.com/ugd/902d29_db7a56a31cb74a1d8d95b612db92bb56.pdf
    • https://static.usrfiles.com/ugd/73c254_743bdd5f05584a4aae293f364a6edcd3.pdf
    • https://cdn.shopify.com/s/files/1/0432/5546/4104/files/contract_engineering_jobs.pdf
    • https://cdn.shopify.com/s/files/1/0431/6214/0840/files/53090989756.pdf
    • https://static.usrfiles.com/ugd/1be480_397779487ba047819cd1900c7dad1298.pdf
    • https://static.usrfiles.com/ugd/0a052f_a0f0bb9a2d914d6c9b93dc4046de6e3e.pdf
    • https://static.usrfiles.com/ugd/b8c837_9b3d13dcd993423f80cf3f98d94eaba1.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_006_off0000f024.bin
39489c3c15aa4a75edf696994ed4f1689b3897a6240f02c5a504d89f3698abcc
decompressed-pdf-stream PDF FlateDecoded stream at offset 0xF024 23392 bytes
font_00_sfnt_off0000ab3d.bin
9b0352d42fd9d4a34220a537f01f936f2047a9688ffdef586761ff4e471e886d
pdf-font-stream PDF embedded font (sfnt) at offset 0xAB3D 3936 bytes
font_01_sfnt_off0000b859.bin
68c57bb7240d3bcb154c08f70b68985bf3842c3c5439e375608241b059030b90
pdf-font-stream PDF embedded font (sfnt) at offset 0xB859 5336 bytes
font_02_sfnt_off0000ca8c.bin
fdc419658244b33acd2b8020af3ab6d3e86cecb46eb37541d02ce612a176d686
pdf-font-stream PDF embedded font (sfnt) at offset 0xCA8C 11032 bytes