Malicious PDF — malware analysis report

Static analysis result for SHA-256 e782a98e87e081dc…

MALICIOUS

PDF

40.6 KB Created: 2020-09-04 13:03:32 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e8fd3fb0d84b0024917437203491086a SHA-1: a640a81969e636545ad804b6b71456d7e6ba1fd8 SHA-256: e782a98e87e081dcc1e1b1661fcb0cc375ab1b0b5ecae9cbe6e1fd73ea9d86f4
130 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.001 User Execution: Malicious Link T1059.001 Command and Scripting Interpreter: PowerShell

The PDF file contains a mass external link farm, with a critical heuristic firing for PDF_MALICIOUS_REDIRECTOR_LINK. The primary malicious URL identified is https://ttraff.me/wix?keyword=sustainability+reporting+singapore+rules, which is likely used to redirect users to malicious content. The presence of a visual download button lure further supports the social engineering aspect of this attack.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/wix?keyword=sustainability+reporting+singapore+rules
    • https://static.usrfiles.com/ugd/77eba6_6aa85827fce24d52a44327ccd6e75da7.pdf
    • https://static.usrfiles.com/ugd/a43ec6_f4e2fc5f09cc4b76becdac7d577cf271.pdf
    • https://static.usrfiles.com/ugd/9d66c7_aea2f72ae8c245d9839c7107cbd780ee.pdf
    • https://static.usrfiles.com/ugd/8da65f_ff77ec528a024ac78aaaafa439281201.pdf
    • https://static.usrfiles.com/ugd/dbbfd0_3944f0cfcdfd4510b11e6b30fd6945b2.pdf
    • https://static.usrfiles.com/ugd/ed64d2_253ef0ee93284f969e2b2277f1fe647e.pdf
    • https://static.usrfiles.com/ugd/2813e2_db2392266c8241e18d93393dfbe7681d.pdf
    • https://static.usrfiles.com/ugd/b8c837_f6669a76336f4ab58e9517c4f2a0b01a.pdf
    • https://static.usrfiles.com/ugd/b8c837_2ac059802fc34f08872ac0a45fc587c4.pdf
    • https://static.usrfiles.com/ugd/b8c837_babdc4933463447196e67db98e992f05.pdf
    • https://static.usrfiles.com/ugd/136d07_83f1178494a94b2eb9801134596433f4.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006049.bin
81d46f6db961b8d0f0176d788681605e86a13f8505d8d2f4a353b432777258b6
pdf-font-stream PDF embedded font (sfnt) at offset 0x6049 5332 bytes
font_01_sfnt_off0000727d.bin
4ee17a37023254f8112d15b9b0557e792e070d5a8546f91047ea993d623158c6
pdf-font-stream PDF embedded font (sfnt) at offset 0x727D 10332 bytes