Malicious PDF — malware analysis report

Static analysis result for SHA-256 cf2c7e1a1310b962…

MALICIOUS

PDF

47.5 KB Created: 2020-09-01 00:09:39 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 48acb52f3516fe4d3f29b9fb1e431742 SHA-1: 5169c4fdc412a14a041b71a6e5776c18460b9062 SHA-256: cf2c7e1a1310b9627580a67ad7c7b44d1eb934ce8c2fe50ae8611ab9d1ad463d
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1200 Hardware Add-in T1059.001 PowerShell

The PDF contains a heuristic firing for a malicious redirector link pointing to 'ttraff.cc'. This link is presented within the document body, disguised as a download for 'guitar chords for dummies pdf'. The PDF also contains a link farm heuristic, indicating a large number of external links, many of which point to 'static.usrfiles.com'. The primary malicious IOC is the redirector URL, which likely leads to further malicious content.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=guitar+chords+for+dummies+pdf
    • https://static.usrfiles.com/ugd/865d50_bc0fadd4f9ab42a9a75947f2c34bfcb8.pdf
    • https://static.usrfiles.com/ugd/b0b521_37b0ac4405df442eb039fad7a8b7bd4e.pdf
    • https://static.usrfiles.com/ugd/a298ce_11ff8ccc53e94c808e93f7de42cce498.pdf
    • https://static.usrfiles.com/ugd/bf650e_5d95462df1ad40ad9e7970985c198d4a.pdf
    • https://static.usrfiles.com/ugd/dfb5f8_f3ced4755bca4b00ac0bafb8dc775aa3.pdf
    • https://cdn.shopify.com/s/files/1/0429/5580/0739/files/64470341946.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/41718344304.pdf
    • https://static.usrfiles.com/ugd/0cd3a8_5f960b398e8c417182250fbdc71fb0fc.pdf
    • https://static.usrfiles.com/ugd/3aee12_f358e90a0eea44ad92305bf797fe6776.pdf
    • https://static.usrfiles.com/ugd/3aee12_7236c8d501e44616ae9179d28ba50d13.pdf
    • https://static.usrfiles.com/ugd/ab922d_5cd0d809ec654fd9a77d32488cd14d1c.pdf
    • https://static.usrfiles.com/ugd/b8c837_f369167a16424859b507f67f9304f693.pdf
    • https://static.usrfiles.com/ugd/565485_48008b76cfb849e0a0ae2d11bd003c99.pdf
    • https://static.usrfiles.com/ugd/cac9e4_92d80ef2c3fa451b81a128bf2247e564.pdf
    • https://static.usrfiles.com/ugd/51c472_4719c555b9f84f26aeccf50ca12249f1.pdf
    • https://static.usrfiles.com/ugd/cc089a_b69162c11e1a4d2f8d5b2d7f0ad15fc6.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000733c.bin
c5c496ea4aee2c4517b8d740cdfd655b4a9b14bec7fdf3a7b6cafa42c30cb9b5
pdf-font-stream PDF embedded font (sfnt) at offset 0x733C 5392 bytes
font_01_sfnt_off00008562.bin
6d2a3a16cc464ce72cf05976c7f96a31c93af2202e0dc760c37a694345e222ee
pdf-font-stream PDF embedded font (sfnt) at offset 0x8562 1800 bytes
font_02_sfnt_off00008df2.bin
8328284d665576ae47e6f81b13830218228e438c4ebc832dd4289308f76745f9
pdf-font-stream PDF embedded font (sfnt) at offset 0x8DF2 10032 bytes