Malicious PDF — malware analysis report

Static analysis result for SHA-256 e1bda5bdadd5ac14…

MALICIOUS

PDF

56.0 KB Created: 2020-08-30 11:43:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3aa2416ab1adae687110165b9a49e779 SHA-1: 6fbc8fac79978112744494d2859a0683744eb4fc SHA-256: e1bda5bdadd5ac1492db64eb0b271cea9428dc9f5fd23f6c6e27ef8258a1a75e
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/wix?keyword=time+to+beat+hollow+knight'. This indicates an attempt to direct the user to a malicious site. The document body also contains this URL, reinforcing the lure. The presence of numerous external PDF links, while many are benign, suggests a link farm tactic, potentially to obscure the malicious destination.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=time+to+beat+hollow+knight
    • https://static.usrfiles.com/ugd/b8c837_d9843def85c248e6a25c0dfb447b3b62.pdf
    • https://static.usrfiles.com/ugd/b8c837_f0b5ff1970514d519f44d030132db0d9.pdf
    • https://static.usrfiles.com/ugd/b8c837_fca9b70c27e743ee82280ac60cf0ac31.pdf
    • https://static.usrfiles.com/ugd/b8c837_cdb8c915d5d04509a775216ffb8b7c2c.pdf
    • https://cdn.shopify.com/s/files/1/0437/2067/1400/files/55878277212.pdf
    • https://cdn.shopify.com/s/files/1/0439/8609/2190/files/bioplasticos_en_mexico.pdf
    • https://cdn.shopify.com/s/files/1/0435/9425/2456/files/treatment_of_epilepsy_in_childhood_pdf.pdf
    • https://cdn.shopify.com/s/files/1/0428/8797/0975/files/86914968919.pdf
    • https://cdn.shopify.com/s/files/1/0432/4737/0402/files/kulegavu.pdf
    • https://static.usrfiles.com/ugd/5cf23b_33be10b414c548f8be31123eb1c782a1.pdf
    • https://static.usrfiles.com/ugd/10b11f_17a209bf0e3a45bd9b0fb0015ed09a0c.pdf
    • https://static.usrfiles.com/ugd/b8c837_48d56d99f5db44099dd19650b14b9f03.pdf
    • https://static.usrfiles.com/ugd/735189_264a5a96340d444b8ee908ace58aa696.pdf
    • https://static.usrfiles.com/ugd/4b7290_f143fef187d841c892187f014c0a9740.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000916d.bin
e7dc8966f08500f6b8d41ee46874273642017a87da091c7acfd4e62aa5253b08
pdf-font-stream PDF embedded font (sfnt) at offset 0x916D 4860 bytes
font_01_sfnt_off0000a1db.bin
e9cfd96d5f66ed2c8184acbdbeef8f68ceef6bd85e7d23eff83c887a6a20b63f
pdf-font-stream PDF embedded font (sfnt) at offset 0xA1DB 10360 bytes
font_02_sfnt_off0000c54e.bin
4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0xC54E 4324 bytes