Malicious PDF — malware analysis report

Static analysis result for SHA-256 bdbc86ee24080596…

MALICIOUS

PDF

44.6 KB Created: 2020-08-30 18:05:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: fc6892add4ef81411813cc53b424b1de SHA-1: 955b79de761b06ef803e38a8425131b22b4a59e5 SHA-256: bdbc86ee240805962f6604e3689331aa2a942d96c8f3c5ca3e8754350bdb2f3b
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF file contains a lure related to an 'attestation letter for certificate' and embeds numerous external links, with one identified as a malicious redirector. The heuristic 'PDF_MALICIOUS_REDIRECTOR_LINK' indicates that the link https://ttraff.com/wix?keyword=attestation+letter+for+certificate points to known malicious infrastructure. The 'PDF_SEO_LINK_FARM' heuristic suggests a large number of outbound links, likely for SEO manipulation or to host further malicious content. The document body, though partially corrupted, also contains the malicious URL, reinforcing the phishing or redirection attempt.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=attestation+letter+for+certificate
    • https://static.usrfiles.com/ugd/2274a7_e00a11c25ea4469f982ffa3df84c9b11.pdf
    • https://static.usrfiles.com/ugd/b8c837_efab7b681d9a43dfa11e5b6b10af5f43.pdf
    • https://static.usrfiles.com/ugd/b8c837_65578ffde2174e11a61e8ae217c79e0e.pdf
    • https://static.usrfiles.com/ugd/05900a_eebd5a6e78ee477aa42bd9141ec5e785.pdf
    • https://cdn.shopify.com/s/files/1/0434/7337/1300/files/gaziwaxubeloguxut.pdf
    • https://cdn.shopify.com/s/files/1/0428/3708/2271/files/92735758766.pdf
    • https://cdn.shopify.com/s/files/1/0437/0015/8629/files/82309303598.pdf
    • https://cdn.shopify.com/s/files/1/0430/7573/1616/files/duwarikuw.pdf
    • https://cdn.shopify.com/s/files/1/0430/2585/8714/files/blood_hunter_2._1.pdf
    • https://cdn.shopify.com/s/files/1/0431/5866/7415/files/accounting_text_and_cases_13th_edition.pdf
    • https://cdn.shopify.com/s/files/1/0437/5537/2695/files/tozenuba.pdf
    • https://cdn.shopify.com/s/files/1/0435/8638/8123/files/apostol_s_calculus.pdf
    • https://cdn.shopify.com/s/files/1/0440/3986/4485/files/53503574601.pdf
    • https://static.usrfiles.com/ugd/23b571_5209e5d1aaac454c95ebc9b449a72953.pdf
    • https://static.usrfiles.com/ugd/b8c837_f557e4f7c1954be19abf8718eafa25c8.pdf
    • https://static.usrfiles.com/ugd/7e0eb0_dbd0173a5f7f49aebe7a34949b38c487.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000720a.bin
9eba3b471c43aa702b861da8621a474201ab34558387ae219dda705bc02145de
pdf-font-stream PDF embedded font (sfnt) at offset 0x720A 4864 bytes
font_01_sfnt_off0000829b.bin
65cf44a47b0aeea3be6017e37e9149624bf2229127fbe99146dd9fad79ca2834
pdf-font-stream PDF embedded font (sfnt) at offset 0x829B 10524 bytes