Malicious PDF — malware analysis report

Static analysis result for SHA-256 f581416c4681e9ef…

MALICIOUS

PDF

38.9 KB Created: 2020-08-30 10:26:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 621d9cca85133ffa6935073cfbde149d SHA-1: 0237af8f6135573499c8ccfbeb00af2c0935bad8 SHA-256: f581416c4681e9ef7ce17ee2ffca0a992beb1b0374c92d241bf8cf349b121925
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link pointing to 'ttraff.com'. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded links, many pointing to 'static.usrfiles.com'. The document body is heavily obfuscated but contains the same redirector URL. The primary attack pattern appears to be SEO manipulation or redirection to malicious content via a link farm.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=den+hartog+mechanical+vibrations
    • https://static.usrfiles.com/ugd/12f4eb_f094ecad00aa4ffab8745b210e383282.pdf
    • https://static.usrfiles.com/ugd/4c76bf_4adbb3da44444ffebb83a876a2117f36.pdf
    • https://static.usrfiles.com/ugd/b8c837_0502482389fa47d68f232241c21bd58a.pdf
    • https://static.usrfiles.com/ugd/b8c837_58a5cd592390491e80ecaffb9388e4cf.pdf
    • https://static.usrfiles.com/ugd/b8c837_8314c533b0d54bb79beabd900d76cdd8.pdf
    • https://static.usrfiles.com/ugd/80c1db_8e0eca6cecea4dc7a32446b61406aa96.pdf
    • https://cdn.shopify.com/s/files/1/0431/0004/5469/files/burnout_3_ost.pdf
    • https://cdn.shopify.com/s/files/1/0431/8127/7345/files/bilade.pdf
    • https://cdn.shopify.com/s/files/1/0428/6673/7311/files/32513443597.pdf
    • https://cdn.shopify.com/s/files/1/0428/8043/4342/files/perow.pdf
    • https://cdn.shopify.com/s/files/1/0437/7939/1637/files/97058877311.pdf
    • https://static.usrfiles.com/ugd/b8c837_c17d130facb3441690e2030855741e61.pdf
    • https://static.usrfiles.com/ugd/b8c837_309a309bfe6143808f7624433e6b85f0.pdf
    • https://static.usrfiles.com/ugd/c7a620_b3090a11d0ac4c0482eb58d6adbc1130.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005b74.bin
d13ef9cbba70228b059d90e8a48a73fc7397638a3707e77aea1bb41f0af71b56
pdf-font-stream PDF embedded font (sfnt) at offset 0x5B74 5412 bytes
font_01_sfnt_off00006db7.bin
d5280cdaffac758b73b3de3d0c30562c74b73f3895b669404767719120df6fae
pdf-font-stream PDF embedded font (sfnt) at offset 0x6DB7 9784 bytes