Malicious PDF — malware analysis report

Static analysis result for SHA-256 c820b1ec28ce65b4…

MALICIOUS

PDF

43.1 KB Created: 2020-09-18 04:01:05 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a069168f5fe576cdfcffe0291a8592a0 SHA-1: 15264735a426590909ee6353287af20df899f72d SHA-256: c820b1ec28ce65b4b8e455ab5edc08b1523656f8ea2e0903c4768999363b7e46
140 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.me/wix?keyword=anderson+county+detention+center+clinton+tn'. Additionally, another critical heuristic indicates a PDF link farm, with the first URL being 'https://1a8cb9ba-da36-4a69-86a4-14be0fd86702.filesusr.com/ugd/9d869b_90e1b64c70cf44dbbd3007db56b9cfd5.pdf?index=true'. The document body, though heavily obfuscated, also contains these URLs, reinforcing the malicious intent. The presence of a callback lure heuristic further suggests a phishing or scam context.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=anderson+county+detention+center+clinton+tn
    • http://simek.stjohnsmag.com/uploads/1/3/1/0/131070450/4493119.pdf
    • http://rezodapeb.bellaspeechsensoryworldinc.com/uploads/1/3/0/7/130775455/21fa216e5b6.pdf
    • http://files.judiculbertson.net/uploads/1/3/0/7/130740017/mozapabebiw_femunu_fekamibovijelig_pigigurob.pdf
    • http://files.wobcffl.com/uploads/1/3/2/6/132681295/43296896a5.pdf
    • https://1a8cb9ba-da36-4a69-86a4-14be0fd86702.filesusr.com/ugd/9d869b_90e1b64c70cf44dbbd3007db56b9cfd5.pdf?index=true
    • https://d0af2e0d-e4dd-4e87-8c5a-7f810eda9133.filesusr.com/ugd/49be48_35020b2b8064462e9b22b11af6c229f3.pdf?index=true
    • https://9199dbb9-139f-4f39-a0d7-03685820eac5.filesusr.com/ugd/70c1ec_dc6c56f3b79f4c10b317574c2d7161aa.pdf?index=true
    • https://4d6b012e-b16d-41c9-8a5b-04ad369c5862.filesusr.com/ugd/4fea5c_4bed2ea4c9354acaba240713ad3d2d78.pdf?index=true
    • https://1f298257-c138-4efe-90b2-ba3282424c11.filesusr.com/ugd/f0b6b3_f65998abce784663bc9f0b301872af78.pdf?index=true
    • https://a6924d86-a752-46d7-98ec-9538ced8b26e.filesusr.com/ugd/2ac701_9fd74e86f1ca4b9d98b9af047b37f805.pdf?index=true
    • https://30a7ecc5-52b5-4616-bdce-43521febf612.filesusr.com/ugd/d90490_e19472322ca44425be4e1dc1f5f473ea.pdf?index=true
    • https://8927e9e6-a05c-408b-92fd-e469fb3e9630.filesusr.com/ugd/370ea2_b75b5b0212ab44979365234ac9569f88.pdf?index=true
    • https://1743fb3b-aeb4-49c0-aa69-e7f6e4823a36.filesusr.com/ugd/bca722_b67d6f8ed32c43f5a1174822e45cb311.pdf?index=true
    • https://2b8e1504-cc84-4a94-acf5-835e6c3aba84.filesusr.com/ugd/1b9faa_0b4f9f007dcd4cb4998de52f7040119b.pdf?index=true
    • https://e6db0a3d-7b7a-41f8-83de-c11dde99efc7.filesusr.com/ugd/5a1791_73654d5b416a44ea88b766308d6cbffd.pdf?index=true
    • https://9a3ea4c1-6103-47ac-8897-995125d966b6.filesusr.com/ugd/2ca22b_bc3068596c0e4916ae753cd6c737eb5e.pdf?index=true
    • https://54421929-35da-4e7c-890c-55a460f49b62.filesusr.com/ugd/9bd82e_139655deab9e4741b016f43d47aebc1a.pdf?index=true
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://9a3ea4c1-6103-47ac-8897-995125d966b6.filesusr.com/ugd/2ca22b_bc3068596c0e4916ae753cd

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006afa.bin
f93c5e8ec5b9cddee5473e0a4aa587a5a3bf0762d14e2591df4ca29de104b723
pdf-font-stream PDF embedded font (sfnt) at offset 0x6AFA 4816 bytes
font_01_sfnt_off00007b74.bin
8be143a4821dcc544a61877a9fa317df369a7708a198b92786d46e6785cce85b
pdf-font-stream PDF embedded font (sfnt) at offset 0x7B74 10456 bytes