Malicious PDF — malware analysis report

Static analysis result for SHA-256 f42e8b85cb324250…

MALICIOUS

PDF

42.3 KB Created: 2020-09-01 11:15:17 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f11ff145718353ec8161bf78a19e52be SHA-1: 0aa9fa1197548814c5e3b392b45edfd2104892b8 SHA-256: f42e8b85cb3242500a9de0b2e957e99ba93d2997bcc9e9d590c5019865b6ec8b
162 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link, directing users to a URL that appears to offer cracked software. It also contains a high heuristic for a password-protected archive lure, suggesting the PDF itself is a decoy to facilitate the download of a password-protected malicious payload. The document body, though heavily obfuscated, contains the same lure URL and references to other PDF files hosted on static.usrfiles.com, which are likely part of a link farm to improve search engine ranking for the malicious lure.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=abbyy+finereader+free++with+crack
    • https://static.usrfiles.com/ugd/b8c837_03c0f31937d141bfbe664aea726c2791.pdf
    • https://static.usrfiles.com/ugd/8acad3_7f8fb43447a04629aaed01cc712a22e1.pdf
    • https://static.usrfiles.com/ugd/dc98cc_d7400a1b159a479aa3f8314fbb4a4a1b.pdf
    • https://static.usrfiles.com/ugd/b8c837_17deed89015940d9a6f183a05e92f7a5.pdf
    • https://static.usrfiles.com/ugd/5899d5_2470b344e3184e55aeb528a4475e5c47.pdf
    • https://static.usrfiles.com/ugd/b3bc21_a14816db084441fd86e4b6429e82901b.pdf
    • https://static.usrfiles.com/ugd/9c43ec_374d5f9d01b34b10899494b8fef84c7d.pdf
    • https://static.usrfiles.com/ugd/277b62_424d3e3367ec4a3f888c81c73f265a5e.pdf
    • https://static.usrfiles.com/ugd/2f8cea_8a84288a052b4559af4304c9b3a0dc76.pdf
    • https://static.usrfiles.com/ugd/f459ea_bc8d47f56b554e93b66dc195f48e9b0a.pdf
    • https://static.usrfiles.com/ugd/b8c837_3bd5f229bb2d4ace8ce9d91a1189196a.pdf
    • https://static.usrfiles.com/ugd/b8c837_bf72fc765e04470a8f2e65bb3ff3554b.pdf
    • https://static.usrfiles.com/ugd/b8c837_0855aecdad9f4b0aa0a1147d93c609aa.pdf
    • https://static.usrfiles.com/ugd/225520_d3776d3181684732a05b160fe03614b0.pdf
    • https://static.usrfiles.com/ugd/21e6f2_4ef6c1bf5c29431fb3e439fc5204dfba.pdf
    • https://static.usrfiles.com/ugd/80bfa9_15d0737085c640aba2d67206d93f2929.pdf
    • https://static.usrfiles.com/ugd/3e9e83_1e037c880b9f4218ac1fcf5630ad07e5.pdf
    • https://static.usrfiles.com/ugd/b8c837_31acf244f30c48d9ba84016a7ceea100.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000670d.bin
689270508267ebdc9a05817f5fa5f94033bebdbc3890921d3b45e7eb9bb720b9
pdf-font-stream PDF embedded font (sfnt) at offset 0x670D 5288 bytes
font_01_sfnt_off0000791c.bin
c4556c23752d3dba02e3ea78bc707dce48812a3f0a5b35226079b2bac9e86b65
pdf-font-stream PDF embedded font (sfnt) at offset 0x791C 10204 bytes