Malicious PDF — malware analysis report

Static analysis result for SHA-256 f3467a3373589e44…

MALICIOUS

PDF

37.8 KB Created: 2020-08-29 00:28:02 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 878dee6ffcbee07b4916c1f56b0cf066 SHA-1: a9363e17ca812330aa652e5f9f9d74b58a2b44bc SHA-256: f3467a3373589e44b18821b78145ca82c51de2d60eaf09792f1ff88ff0428120
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a link disguised as a lure for 'Brawlhalla redeem codes 2016'. This link, 'https://ttraff.cc/wix?keyword=brawlhalla+redeem+codes+2016', is flagged as a malicious redirector. The document also functions as a link farm, pointing to numerous other PDFs hosted on static.usrfiles.com, likely to manipulate search engine results or distribute further malicious content. The primary intent appears to be directing users to malicious infrastructure through a deceptive lure.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/wix?keyword=brawlhalla+redeem+codes+2016
    • https://static.usrfiles.com/ugd/b8c837_2bb73b75561047939d52aa76e6e8a4b1.pdf
    • https://static.usrfiles.com/ugd/b8c837_dbd2e2cfcdf24fdd93365e75120b49fd.pdf
    • https://static.usrfiles.com/ugd/b8c837_d68c6f48aa114e01934e7c0366e1c7f3.pdf
    • https://static.usrfiles.com/ugd/b8c837_e02019584a954817afa1533844b0729b.pdf
    • https://static.usrfiles.com/ugd/b8c837_61705d94a7234f11af07d7fbdb21bd2c.pdf
    • https://cdn.shopify.com/s/files/1/0435/0600/8216/files/73049152759.pdf
    • https://cdn.shopify.com/s/files/1/0435/1302/0570/files/biostatistics_question_bank.pdf
    • https://cdn.shopify.com/s/files/1/0432/1594/5890/files/napuzefumatipoliwamegix.pdf
    • https://cdn.shopify.com/s/files/1/0431/0492/7905/files/netiwazamalifupagikuviju.pdf
    • https://cdn.shopify.com/s/files/1/0465/1086/6582/files/9709985543.pdf
    • https://static.usrfiles.com/ugd/b8c837_1bb02df74e0c4388b2052b7cbe492e65.pdf
    • https://static.usrfiles.com/ugd/b8c837_f3b654f51e954338b4cbf57c9b712593.pdf
    • https://static.usrfiles.com/ugd/b8c837_18a7fe7089734bb1a7b8b4552ffa36cc.pdf
    • https://static.usrfiles.com/ugd/b8c837_963d92698c7844c393e7377a5d1421e7.pdf
    • https://static.usrfiles.com/ugd/b8c837_5c6160b6537646af81d48374e8119561.pdf
    • https://cdn.shopify.com/s/files/1/0433/0664/7717/files/dawn_on_a_distant_shore.pdf
    • https://cdn.shopify.com/s/files/1/0446/7536/7065/files/download_hls_streaming_video.pdf
    • https://cdn.shopify.com/s/files/1/0431/5221/2130/files/download_free_xxxmovies.pdf
    • https://cdn.shopify.com/s/files/1/0428/5428/5479/files/louie_simmons_reverse_hyper.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://cdn.shopify.com/s/files/1/0428/5428/5479/fil

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000539a.bin
61749b6c0d093bb2741531ec5a4c381faaaf4c0ad7d22e097db3054165ad8fe0
pdf-font-stream PDF embedded font (sfnt) at offset 0x539A 5800 bytes
font_01_sfnt_off00006741.bin
7848f1cc7f5ffd18864c4fdf64d6802faf2320b7716e868f51e60faabf2b690d
pdf-font-stream PDF embedded font (sfnt) at offset 0x6741 10280 bytes