Malicious PDF — malware analysis report

Static analysis result for SHA-256 241dd836d0b0b4df…

MALICIOUS

PDF

50.7 KB Created: 2020-09-01 02:01:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 8524e8abafa0a525241845517fb98551 SHA-1: 42574aed56c098c1400f94c1b6a31701e0fc4a21 SHA-256: 241dd836d0b0b4df3ad302e2fea754314c39349602f51c3216938e3d5ddd9176
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a critical heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.ru/wix?keyword=accenture+technology+vision+2018+pdf'. This indicates the document's primary purpose is to redirect users to a potentially harmful site. The document body, though heavily obfuscated, contains this URL, reinforcing the malicious intent. The presence of numerous other links, many hosted on static.usrfiles.com, suggests a link farm or SEO poisoning tactic to increase the visibility of the malicious redirector.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=accenture+technology+vision+2018+pdf
    • https://static.usrfiles.com/ugd/b8c837_7de288fed27540c89c218e76bc81b2e8.pdf
    • https://static.usrfiles.com/ugd/3b7182_5bfe9dd4f9154eecbb217c3310fbba3e.pdf
    • https://static.usrfiles.com/ugd/de02f3_e73946c849354692b7127d5da5d70c93.pdf
    • https://static.usrfiles.com/ugd/3aee12_808cdee66dda45eab23dba38ef23c367.pdf
    • https://static.usrfiles.com/ugd/73c254_5f168c1921bd494a8ee70fe26e5bd913.pdf
    • https://cdn.shopify.com/s/files/1/0433/5045/8520/files/sozetodilubufunadiw.pdf
    • https://cdn.shopify.com/s/files/1/0433/2240/9125/files/zopuvevusupirusen.pdf
    • https://cdn.shopify.com/s/files/1/0461/4337/3480/files/48486226164.pdf
    • https://cdn.shopify.com/s/files/1/0430/6914/5241/files/tazamipibotewomamudoji.pdf
    • https://static.usrfiles.com/ugd/b8c837_d58e55c4da084915a04127f1b72669aa.pdf
    • https://static.usrfiles.com/ugd/96768c_e0d062366e7f41e09d591998cb1a76b9.pdf
    • https://static.usrfiles.com/ugd/cbe7f7_6d5c61752edf45d494e8691c90f6f14e.pdf
    • https://static.usrfiles.com/ugd/4b7290_bbecc1307bd9426281901940ed06dd25.pdf
    • https://static.usrfiles.com/ugd/99965f_1222529cde424113ac3eee9a1054e83a.pdf
    • https://static.usrfiles.com/ugd/b8c837_283e40783a034a528e2f92a6d43a4b39.pdf
    • https://static.usrfiles.com/ugd/067ecb_8129ce06ae854f079de59499eb8a4e8d.pdf
    • https://static.usrfiles.com/ugd/3aee12_b655e5430f3b4cb5992cb586f5c19665.pdf
    • https://static.usrfiles.com/ugd/b8c837_cdafefd7f2a64ac0a739e61e44f10ec9.pdf
    • https://static.usrfiles.com/ugd/0d002d_d6c4d896b3084d01b7d8fd205e47ef68.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000867f.bin
19903d501e6e870880d1f80b753968757fee0a3b8e1af54d2abdb942e71e9517
pdf-font-stream PDF embedded font (sfnt) at offset 0x867F 5876 bytes
font_01_sfnt_off00009aa2.bin
a78f6cb17b0f548f238024f8c305e9c1fbc1dcd04c2fb3d1916b28d588971928
pdf-font-stream PDF embedded font (sfnt) at offset 0x9AA2 10240 bytes