Malicious PDF — malware analysis report

Static analysis result for SHA-256 d6555d63c737bf88…

MALICIOUS

PDF

47.7 KB Created: 2020-09-06 14:30:30 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 894fa3d3c8b21724626573ff1eb92592 SHA-1: 8ad46793ca7e4323accbc88ebd12601b13be6513 SHA-256: d6555d63c737bf88e0058483656ae76754752fe9693d559a2f722aeca7c72512
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing for PDF_MALICIOUS_REDIRECTOR_LINK, indicating it points to a known malicious redirector. Additionally, PDF_SEO_LINK_FARM indicates a large number of external links, likely for SEO manipulation or to obscure the malicious destination. The primary malicious URL identified is https://ttraff.club/wix?keyword=westland+survival+mod+apk+happymod, which is presented in the document body as a lure for software downloads.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=westland+survival+mod+apk+happymod
    • https://static.usrfiles.com/ugd/5d2cf3_14c43af1debe4ba29def33b66ac4554d.pdf
    • https://static.usrfiles.com/ugd/e33828_fd8945a2e9d443afab834564e2f494c0.pdf
    • https://static.usrfiles.com/ugd/77941b_8fe883252ec14d7f88289f6472934feb.pdf
    • https://static.usrfiles.com/ugd/409ca8_ac7aa98a21684fdd8ca7e69616ba3f40.pdf
    • https://static.usrfiles.com/ugd/c1108c_8319def948dd44fd9637f5c2bd358c77.pdf
    • https://static.usrfiles.com/ugd/e49726_8d6b256b0d6a4ed2b421ed75ea22d4f1.pdf
    • https://static.usrfiles.com/ugd/b8c837_39d35689cf7343b5be459bd2bf20f237.pdf
    • https://static.usrfiles.com/ugd/3eed2b_a77ab62f82c2433486b5c363f0fe1788.pdf
    • https://static.usrfiles.com/ugd/865d50_56df7f3ee21b453f80b35574bbc854b8.pdf
    • https://static.usrfiles.com/ugd/a4d998_56d9c964cca54fd2aec06293412f2581.pdf
    • https://static.usrfiles.com/ugd/6a7407_f5204976009944f082168d03f5b501b7.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005ed4.bin
f558610a1f025b48806dca4dbc2f277cc9eb10670985cf1c4121027e487ba1d5
pdf-font-stream PDF embedded font (sfnt) at offset 0x5ED4 5436 bytes
font_01_sfnt_off00007130.bin
8c5f596b751b5df4f2110414aaa1c630b67d90a9bc37611b1def66c0a15a082c
pdf-font-stream PDF embedded font (sfnt) at offset 0x7130 2060 bytes
font_02_sfnt_off00007ac8.bin
1985a2d4d4b707a082c9e72960785ae4a367cd40b186f908023d607af1252c8a
pdf-font-stream PDF embedded font (sfnt) at offset 0x7AC8 9904 bytes
font_03_sfnt_off00009cde.bin
9af6fc3bf9d751f70540aea0fa47faa159a3604992cda23d2adcda3ffc5346b2
pdf-font-stream PDF embedded font (sfnt) at offset 0x9CDE 16092 bytes