Malicious PDF — malware analysis report

Static analysis result for SHA-256 e571d70bda60fd94…

MALICIOUS

PDF

47.4 KB Created: 2020-08-31 01:25:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3d521595174c20bc0b68620d4aa35996 SHA-1: 2541b0b44b0d34abc59f533e7b26b7a5869ad7d8 SHA-256: e571d70bda60fd94494e4d1ae29d631f7fc07a71bfa8b413fe8abf0728c48837
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a heuristic firing for a malicious redirector link, pointing to 'ttraff.com'. The document body, though heavily obfuscated, contains the same URL, suggesting it's the primary lure. The file also exhibits characteristics of a link farm, with numerous embedded links to external PDFs, likely to improve search engine ranking for the lure. No scripts were extracted, and the family is unknown due to the lack of further indicators.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=forever+strong+pelicula+completa+esp
    • https://static.usrfiles.com/ugd/2c608b_4c2a39c8f79a4ddfaaf48dd9a97753c6.pdf
    • https://static.usrfiles.com/ugd/a4e402_cd34229f13684a8790768b3c30263625.pdf
    • https://static.usrfiles.com/ugd/b8c837_ec8fa0036ef7465ea804f506bcd2eca4.pdf
    • https://static.usrfiles.com/ugd/b8c837_a9006dcd00db4a1ba164894ddcfa0059.pdf
    • https://static.usrfiles.com/ugd/b8c837_ef21abd4d10d4d0490ede476d398db3f.pdf
    • https://static.usrfiles.com/ugd/dc51bb_5064395b89a44b1fa30db5d304421284.pdf
    • https://static.usrfiles.com/ugd/20d83a_255d20faff994dbaa59bf2445ce24809.pdf
    • https://static.usrfiles.com/ugd/dc51bb_7da142ecdba847c2a84567cae321c842.pdf
    • https://static.usrfiles.com/ugd/0b46e6_6a04b4bab1744cae863121fd98c50795.pdf
    • https://static.usrfiles.com/ugd/77941b_f71b09fca06a412e94a5c8ad17b5c949.pdf
    • https://static.usrfiles.com/ugd/b8c837_a69288762fdd4d4e88a891d3cd457972.pdf
    • https://static.usrfiles.com/ugd/8c0e65_79b9d4a03e2c4be4924fa0237ad8b8b7.pdf
    • https://static.usrfiles.com/ugd/b8c837_e60d38d172564e7582d1c6a0d27d4e02.pdf
    • https://static.usrfiles.com/ugd/9ea91e_725e21f5b5b049c3bd190f2390e176b0.pdf
    • https://static.usrfiles.com/ugd/b8c837_8c4eed335fd642a4af7c3d861c14881c.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005ca7.bin
048fb1891f432488516cd811e7b04d68e7d39e548ca3495625137f8fb0c23ff4
pdf-font-stream PDF embedded font (sfnt) at offset 0x5CA7 6744 bytes
font_01_sfnt_off00006d8c.bin
fd87b1a1dde59c0030e5996c8a183a5c43ecdb2c3abaeca9c2089dbcf04a9103
pdf-font-stream PDF embedded font (sfnt) at offset 0x6D8C 5268 bytes
font_02_sfnt_off00007f76.bin
5707d448d4eabc7fc5ceec01f6b308e72196173042c8e0a921c879b324cf0831
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F76 16040 bytes