Malicious PDF — malware analysis report

Static analysis result for SHA-256 24502503cd06a21d…

MALICIOUS

PDF

37.5 KB Created: 2020-08-31 02:18:40 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4cc0dcfc42690f093fbaf4ef4bdfe1f8 SHA-1: 3a23acf8a142b2cabc82f69944f18b0e5d26e34b SHA-256: 24502503cd06a21d7e8c4fc60e1049c2164838a529572d6f6fb9e440cfe32122
120 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a link to a known malicious redirector, ttraff.ru, which is disguised with a keyword related to licensing exams. The heuristic PDF_MALICIOUS_REDIRECTOR_LINK confirms this, and PDF_SEO_LINK_FARM indicates a pattern of creating numerous links, likely for SEO poisoning or to obscure the final destination. The document body contains garbled text but includes the malicious URL, suggesting an attempt to obscure the malicious nature of the link.

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=dewalt+electrical+licensing+exam+gui
    • https://static.usrfiles.com/ugd/6908d7_03be236efea4423cb06a28b7ccf368e9.pdf
    • https://static.usrfiles.com/ugd/ae15ca_69c31b65ed574551a1374e6c39710eb9.pdf
    • https://static.usrfiles.com/ugd/07ef24_93481109410c44e49b8ce99ecf2b0fd7.pdf
    • https://static.usrfiles.com/ugd/99afdc_dfb4c8d6967c4464be7416d27edc3174.pdf
    • https://static.usrfiles.com/ugd/a59130_e25720729ba24e0ba9f8b7f07fe8fdbe.pdf
    • https://static.usrfiles.com/ugd/a64c8c_60c4a8698a4a473799ccfd5e2a98b2dd.pdf
    • https://cdn.shopify.com/s/files/1/0438/1956/5216/files/credit_agricole_sa_annual_report.pdf
    • https://cdn.shopify.com/s/files/1/0427/9622/0572/files/totibavokeverufimodotab.pdf
    • https://cdn.shopify.com/s/files/1/0431/9235/2931/files/17242726545.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/41841620016.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000522a.bin
3a640f657630a0d0ea2f19c267dc80efbbdb8b2d1937afa1d5e136ba971d7093
pdf-font-stream PDF embedded font (sfnt) at offset 0x522A 5276 bytes
font_01_sfnt_off00006420.bin
c9436535f479ec4a6d1dcc851b7ae76caab53a0ce92509823fdd0341857723dd
pdf-font-stream PDF embedded font (sfnt) at offset 0x6420 10628 bytes