Malicious PDF — malware analysis report

Static analysis result for SHA-256 d057cb31a8ec9be4…

MALICIOUS

PDF

49.3 KB Created: 2020-08-31 09:53:30 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7f987800cd2b6c66fa0dbec3a914cf57 SHA-1: 5bbef74b80544fbf6a13a6b9868d88e44ed76f3f SHA-256: d057cb31a8ec9be4211f51e91cf84c15ee4369b2f31f56ed7599b6cf76916263
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded links, identified as a PDF link farm. One of these links, https://ttraff.cc/wix?keyword=i+will+survive+sheet+music, is flagged as a malicious redirector. The document body appears to be heavily obfuscated or corrupted, but the presence of the link farm and the malicious redirector strongly suggests an attempt to direct users to harmful content, possibly for SEO poisoning or further exploitation.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=i+will+survive+sheet+music
    • https://static.usrfiles.com/ugd/8127dd_8fd4457fccda4129956a3ffc47971bf6.pdf
    • https://static.usrfiles.com/ugd/b8c837_6081823974ba4625870d29dfba38e714.pdf
    • https://static.usrfiles.com/ugd/b8c837_86fce33d88d24af9b0187d99524497b9.pdf
    • https://static.usrfiles.com/ugd/10e3af_9875e0285fc1418fb0c1ceccb77611d6.pdf
    • https://static.usrfiles.com/ugd/a2e20a_9490135907fd4dbc87b35208f711c80c.pdf
    • https://static.usrfiles.com/ugd/b8c837_8b4006b263a44d7881db2fe21a027e61.pdf
    • https://static.usrfiles.com/ugd/ceb2e8_8e84cd547de641c8aec0f3d6ff6570b6.pdf
    • https://static.usrfiles.com/ugd/432b07_264ea610691146b6ac062093bc374a72.pdf
    • https://static.usrfiles.com/ugd/39cb9d_e7055b1e1c9640398f1cbd512961f9b7.pdf
    • https://static.usrfiles.com/ugd/db93e9_0bd57be146cc4636a2e283c1ae24baea.pdf
    • https://static.usrfiles.com/ugd/a640e9_47328a33c428410f909c95d5bab929fb.pdf
    • https://static.usrfiles.com/ugd/2b25e8_32a2ee4f5c3c42ec8171bf1faca1af9a.pdf
    • https://static.usrfiles.com/ugd/b8c837_dff7c2f01dfb49fc867614780af3b1a9.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000083f9.bin
b9c42164b6f1a7ab1ea17e4605fc25893a0a2b68422e966613c347f193d42d65
pdf-font-stream PDF embedded font (sfnt) at offset 0x83F9 4920 bytes
font_01_sfnt_off0000949b.bin
02470583b328f4f99cdd5a472ea572dbb3f457e2464c1ae618ae390c3f0515f1
pdf-font-stream PDF embedded font (sfnt) at offset 0x949B 10456 bytes