Malicious PDF — malware analysis report

Static analysis result for SHA-256 ec72523e5bb5bcff…

MALICIOUS

PDF

41.0 KB Created: 2020-08-31 05:09:09 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6deeb0f01435baaa3dc55cfa2b377357 SHA-1: dee46e4539cea12d7698990f03fcec4b5f69c81c SHA-256: ec72523e5bb5bcff42f0cfdc16d8676f87ee9055edb89b123e51ca959f93803f
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/wix?keyword=uc+berkeley+personal+history+stateme'. This URL is the primary indicator of malicious intent, likely serving as a lure for phishing or to download further malicious content. No scripts were extracted from this sample, and the document body was heavily obfuscated, making it difficult to determine the exact lure.

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=uc+berkeley+personal+history+stateme
    • https://static.usrfiles.com/ugd/83f04e_814e248fc0df426f882dfe147f411c8c.pdf
    • https://static.usrfiles.com/ugd/08fe48_614cad6df2d945ab9f2997d785d5274c.pdf
    • https://static.usrfiles.com/ugd/2e79a6_cf86ca49f53541588b1e378cf4017b95.pdf
    • https://static.usrfiles.com/ugd/b8c837_b6f2e82f2056476c8f128984f862d88f.pdf
    • https://static.usrfiles.com/ugd/b8bbd7_56ebec7dea294a3f9e164b3ad0e235a9.pdf
    • https://cdn.shopify.com/s/files/1/0428/6539/3820/files/m_l_a_full_form_bengali.pdf
    • https://cdn.shopify.com/s/files/1/0433/0042/1790/files/72913377226.pdf
    • https://cdn.shopify.com/s/files/1/0431/5057/3724/files/business_plan_sample_for_bakery.pdf
    • https://cdn.shopify.com/s/files/1/0434/3827/6760/files/american_english_alphabet_pronunciation.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000624b.bin
89891314e4382cbd260c7a0856402501d80ff621c04731c1fe179ccd9a169914
pdf-font-stream PDF embedded font (sfnt) at offset 0x624B 5468 bytes
font_01_sfnt_off000074b5.bin
8fb90a71d92c104959e96bb1d316d608ba2834b5a4813c2c68f3a2855ae3010f
pdf-font-stream PDF embedded font (sfnt) at offset 0x74B5 10160 bytes