Malicious PDF — malware analysis report

Static analysis result for SHA-256 d9ddb30f27a1d55e…

MALICIOUS

PDF

51.6 KB Created: 2020-08-30 14:07:36 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 61743a5e27bea9f3302f5642b01a27ee SHA-1: f0a00b16a43901a5a0f4c09b3c5263ab6bcf4053 SHA-256: d9ddb30f27a1d55e5e16568a4a96a2e9d387229f98e471524761183760e03913
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to a URL that is disguised as programming instructions. This URL is the primary indicator of malicious intent. The document also contains a large number of embedded links, many of which point to static.usrfiles.com, suggesting a link farm or SEO poisoning tactic to obscure the malicious redirector.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=ge+sunsmart+digital+timer+15312+programming+instructions
    • https://static.usrfiles.com/ugd/451461_956e80dfc70a42df85df4e9835c8a6f4.pdf
    • https://static.usrfiles.com/ugd/0d002d_0030903637b94a5b9beffea7a1201518.pdf
    • https://static.usrfiles.com/ugd/cf79db_b47e0df1ec774c74ac7eff59a25a21d2.pdf
    • https://static.usrfiles.com/ugd/de3d83_aa9910c86798412b9bab2723834b8885.pdf
    • https://static.usrfiles.com/ugd/b8c837_0ad74317eeaf4f898687327d61875ccd.pdf
    • https://cdn.shopify.com/s/files/1/0431/5856/9120/files/collapse_of_ottoman_empire.pdf
    • https://cdn.shopify.com/s/files/1/0433/5943/6951/files/adobe_acrobat_editor_freeware.pdf
    • https://cdn.shopify.com/s/files/1/0433/1202/1657/files/bejunufi.pdf
    • https://static.usrfiles.com/ugd/8d57bd_3cfbb16ff1e248e892695878784f736d.pdf
    • https://static.usrfiles.com/ugd/b8c837_462a32b997ce4dbf8f8589a801444202.pdf
    • https://cdn.shopify.com/s/files/1/0431/4054/6714/files/valores_morales_para_nios.pdf
    • https://cdn.shopify.com/s/files/1/0432/6152/6166/files/8_ball_pool_3._11._0.pdf
    • https://cdn.shopify.com/s/files/1/0431/5843/8056/files/homeostasis_adalah.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007bbf.bin
87586546221dc84850299e02bbc1cfff5c1d3c8468c80524fdfa4bc712cf3625
pdf-font-stream PDF embedded font (sfnt) at offset 0x7BBF 5780 bytes
font_01_sfnt_off00008f52.bin
1f6564bcc4c36564d3c80929bf588bff308ddb9edb9a8632602e7c507a626c54
pdf-font-stream PDF embedded font (sfnt) at offset 0x8F52 10356 bytes
font_02_sfnt_off0000b29c.bin
b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c
pdf-font-stream PDF embedded font (sfnt) at offset 0xB29C 4324 bytes