Malicious PDF — malware analysis report

Static analysis result for SHA-256 bb2dfa42fac64d6c…

MALICIOUS

PDF

43.7 KB Created: 2020-09-01 02:59:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 70d953301eda844e2264d2059a59fff6 SHA-1: e718d8dd65fd951166fc636f640a32e2cabadf08 SHA-256: bb2dfa42fac64d6c70930fc6f3555d5ccb2020ffbb68be60e5e87317bf3207c4
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a significant number of embedded URLs, with one identified as a malicious redirector. The document body, though partially corrupted, appears to be a lure related to formal dresses, suggesting a phishing or spam campaign. The primary malicious indicator is the redirector URL, which likely leads to further malicious content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=formal+dresses+plus+size+for+weddings
    • https://static.usrfiles.com/ugd/b8c837_b01b54efad984754a2f8fd1c8321ce2c.pdf
    • https://static.usrfiles.com/ugd/696b8a_53b7a6d9545e48e1a4e91272e6ab19d2.pdf
    • https://static.usrfiles.com/ugd/1ee69b_031d2421a2ec4a3e8d2ecfbaae2e65a5.pdf
    • https://static.usrfiles.com/ugd/73cb9e_03704fcff5e34ee29060468748db3451.pdf
    • https://static.usrfiles.com/ugd/10e3af_ee403dfdf56849f6ace6b68939b01a23.pdf
    • https://static.usrfiles.com/ugd/b8c837_e17f5444ee2445dbbd3d9962f5a52bed.pdf
    • https://static.usrfiles.com/ugd/b8c837_808ed6bc52454164bcfb3ea2763fa2b2.pdf
    • https://static.usrfiles.com/ugd/b8c837_90cbdfe5e4e44502bfc36b782c597e03.pdf
    • https://static.usrfiles.com/ugd/ae15ca_6e4a2f91e4d941f3bdb96ce5545d8cbc.pdf
    • https://static.usrfiles.com/ugd/ae059d_b4dd84cf1cf441f19eb6db97c31e514c.pdf
    • https://static.usrfiles.com/ugd/3fc21f_39e93b139bcf4c6d8d148579d3018419.pdf
    • https://static.usrfiles.com/ugd/defcb2_9a3694e4d327497c9d30d5f7a81eeb34.pdf
    • https://static.usrfiles.com/ugd/0789d5_4c02f314a3a04ca5b618459e2c625a37.pdf
    • https://static.usrfiles.com/ugd/3b0c81_3fe2786afac8437a98447ad6fa6001c1.pdf
    • https://static.usrfiles.com/ugd/d90490_ca19e2f1d5ac43ef9d712aead339c2bf.pdf
    • https://static.usrfiles.com/ugd/18122d_10dfde71a7ac4e65a4110086dabae560.pdf
    • https://static.usrfiles.com/ugd/0cd3a8_7b5243894f194f968f3515dc4dbaaf27.pdf
    • https://static.usrfiles.com/ugd/0adedf_c3933f8cc0424b97a5799336b8f1c805.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006c5f.bin
33e538847651d7aee13e0d423442afb526723913130e8b8965d7289b0db12d6a
pdf-font-stream PDF embedded font (sfnt) at offset 0x6C5F 5456 bytes
font_01_sfnt_off00007ef8.bin
5fe6cd1e4cae5e0d2b450921c8aaa269060263717fceac8d7cf966f3722a161b
pdf-font-stream PDF embedded font (sfnt) at offset 0x7EF8 10116 bytes