Malicious PDF — malware analysis report

Static analysis result for SHA-256 eddd175b51ea1fec…

MALICIOUS

PDF

44.1 KB Created: 2020-08-31 08:04:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7a6c8bbbef3ac52b2e6ae7d22fb09061 SHA-1: 4b1a18235e9869469edd6b603b249f738e9eb11f SHA-256: eddd175b51ea1fece60dfe04cc10cfb6c03fa36b90877f2fc3a581454da3c93e
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a mass of external links, with one prominent link pointing to a known malicious redirector. The document body, though heavily obfuscated, contains the URL 'https://ttraff.cc/wix?keyword=minecraft+anti+id+conflict+resolver', suggesting a lure to a malicious site. The presence of numerous links to static.usrfiles.com indicates a link farm strategy, likely to improve SEO for malicious content or to obscure the final destination.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=minecraft+anti+id+conflict+resolver
    • https://static.usrfiles.com/ugd/b8c837_a83db85a2edc43d598673373dc4a5f16.pdf
    • https://static.usrfiles.com/ugd/09273f_403041d6e6e74292945b605b7037b4b1.pdf
    • https://static.usrfiles.com/ugd/a86d68_5e149d1dbf5a4ad19427689c58ee09d4.pdf
    • https://static.usrfiles.com/ugd/ace02d_d13368e74a8d4a5cbcf965bcda7adf61.pdf
    • https://static.usrfiles.com/ugd/c068f8_cd2178063403452695158472511cc11e.pdf
    • https://static.usrfiles.com/ugd/eb4c03_27c28192625d4e11b4e36d79097d436c.pdf
    • https://static.usrfiles.com/ugd/d1c05f_d05550a845704f978a2ab31327adda52.pdf
    • https://static.usrfiles.com/ugd/b8c837_77d22d6f68544e30a107b0c1d775dceb.pdf
    • https://static.usrfiles.com/ugd/12dc78_1855ea8452b242e2abc09e6df7cc102c.pdf
    • https://static.usrfiles.com/ugd/b8c837_c6c43a1de9d949f5ad10a1b366588b14.pdf
    • https://static.usrfiles.com/ugd/3b7182_35a790871308483d83a0b700cd567ab4.pdf
    • https://static.usrfiles.com/ugd/217d68_b7be0c5d72c34abab61cbf755232b283.pdf
    • https://static.usrfiles.com/ugd/4b7290_82aa909d8f4942828eeffdf7f2822968.pdf
    • https://static.usrfiles.com/ugd/b8c837_404c24a989354ec29ef1d2ea9a374377.pdf
    • https://static.usrfiles.com/ugd/0a593f_faf0419407eb4f12979ae6393ed6f24e.pdf
    • https://static.usrfiles.com/ugd/9757e7_3a40a6abccaf4fd09ceecbe8f7830ead.pdf
    • https://static.usrfiles.com/ugd/b5aed9_e691a0e82d3f41ff986b4c9a15543425.pdf
    • https://static.usrfiles.com/ugd/b8c837_dd288127f1524a33b729b35cc208c56c.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005924.bin
6034118474f2a54957ce26f573329d05a039aabcfe7f224de915e2571b18eebb
pdf-font-stream PDF embedded font (sfnt) at offset 0x5924 5080 bytes
font_01_sfnt_off00006a7e.bin
171b02f8f09a5510a0596868877ba47901063a51940c51fa190a776a72257cea
pdf-font-stream PDF embedded font (sfnt) at offset 0x6A7E 10280 bytes
font_02_sfnt_off00008dec.bin
9b78b915eb75ef0aea6965a6113565ca1bcac7735c766488ce9f12ff332a71b4
pdf-font-stream PDF embedded font (sfnt) at offset 0x8DEC 16064 bytes