Malicious PDF — malware analysis report

Static analysis result for SHA-256 eb045f4710cd59d5…

MALICIOUS

PDF

45.2 KB Created: 2020-08-29 18:25:58 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3d3d74ea0cd722dc435591ae237423db SHA-1: 6c5eec57ea13894e41622f59c46fb65c669c2925 SHA-256: eb045f4710cd59d5fcfd7a922bc915f5381904d3476a80cd5cbc1a75419c5978
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a large number of embedded links, many of which point to external resources. One critical heuristic firing indicates that the PDF links to known malicious redirector infrastructure, specifically 'ttraff.cc'. The document body, though partially corrupted, contains text related to an exam, likely a lure to encourage clicks on the malicious links. No scripts were extracted, and the primary malicious activity observed is the redirection to potentially harmful websites.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=examen+de+6+grado+de+primaria
    • https://static.usrfiles.com/ugd/b8c837_b6fff296eabc47b6a2a84be79ee9b104.pdf
    • https://static.usrfiles.com/ugd/b8c837_c745da03750044f99e6ccb6407b391d2.pdf
    • https://static.usrfiles.com/ugd/b8c837_a70d14e4017c4f3e9b472845f8e7e8a8.pdf
    • https://static.usrfiles.com/ugd/b8c837_dda40266564a42a2a011b4c308ba3623.pdf
    • https://static.usrfiles.com/ugd/b8c837_b17ce93c91c3442898b4e0ee7fd53639.pdf
    • https://static.usrfiles.com/ugd/b8c837_2c11272175974cbb830bac88bda7f0e5.pdf
    • https://static.usrfiles.com/ugd/b8c837_0a5b9655f91b4c0ba1acc5a93a23f9d9.pdf
    • https://cdn.shopify.com/s/files/1/0433/8548/7525/files/futidote.pdf
    • https://cdn.shopify.com/s/files/1/0450/2369/0916/files/dufanijifuz.pdf
    • https://cdn.shopify.com/s/files/1/0428/5900/4070/files/vujubedodokemunogiz.pdf
    • https://cdn.shopify.com/s/files/1/0430/7822/1973/files/jofavawa.pdf
    • https://static.usrfiles.com/ugd/b8c837_79a4e57205f04ba58e0393a2ba477be0.pdf
    • https://static.usrfiles.com/ugd/b8c837_bfa3c3610ba742a2be88244e439d246f.pdf
    • https://static.usrfiles.com/ugd/b8c837_ef49ec6bf39c4bb486bb80f5e5d64998.pdf
    • https://static.usrfiles.com/ugd/7d21c0_db3fe1e45f394ffeb9b68cbf6892097b.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006ec1.bin
03ff990bc886b90ec2eb2893bbb6cbf9ec4e3038b2ba1e2cfe170819968bf069
pdf-font-stream PDF embedded font (sfnt) at offset 0x6EC1 5248 bytes
font_01_sfnt_off0000808a.bin
3816918c9b48814452baf42adca21e165865ef6e70815e09deea7ea3eb73329a
pdf-font-stream PDF embedded font (sfnt) at offset 0x808A 11648 bytes