Malicious PDF — malware analysis report

Static analysis result for SHA-256 79a0f61d8ef6ba12…

MALICIOUS

PDF

41.6 KB Created: 2020-09-01 07:55:33 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ca19d52a4d9902353037e9f46eee0aed SHA-1: 6bf4b2e1874c76c03db98f7f22ab3c21837cf5e4 SHA-256: 79a0f61d8ef6ba12bbfc3f1bcdc4cffd3f4103b14adc0b1c2a74c3ff127d9635
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link T1059.001 PowerShell

The PDF file contains a mass of external links, many of which point to a redirector service. The primary malicious URL, 'https://ttraff.club/wix?keyword=movie+app+er+for+pc', is presented as a lure for a movie app, likely a social engineering tactic. The presence of a visible LOLBin command execution instruction suggests the PDF is designed to execute commands or download further payloads, although no specific script was extracted to confirm this. The file's structure and link farm indicate a phishing or scam attempt.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visible LOLBin command execution instruction high SE_LOLBIN_RUN_COMMAND
    Document contains instructions or visible command text involving Windows script/execution tools such as PowerShell, mshta, cmd, rundll32, or regsvr32
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=movie+app+er+for+pc
    • https://static.usrfiles.com/ugd/822ecd_04d3b4bf64c24e2b838748f31632675f.pdf
    • https://static.usrfiles.com/ugd/8ab72e_326d285e2d8249869c72286eadbaa071.pdf
    • https://static.usrfiles.com/ugd/2e79a6_ef4f60e4dbea43fc8490cdf74017f463.pdf
    • https://static.usrfiles.com/ugd/ea9bdf_8e7dd3a77637481d810871cee45f1d88.pdf
    • https://static.usrfiles.com/ugd/3aee12_01c3dc59d0394824bf93ed55b03462bd.pdf
    • https://static.usrfiles.com/ugd/9cfd0a_c4590f36d3c84835b596ea3704cb691b.pdf
    • https://static.usrfiles.com/ugd/b8c837_611ab0e9ed0f4056b6505d083582c493.pdf
    • https://static.usrfiles.com/ugd/9c43ec_17ec1125b3cf4b0e92a3fb73089e684c.pdf
    • https://static.usrfiles.com/ugd/4bb894_18eedb51a1ea458882c0072f4c028e5e.pdf
    • https://static.usrfiles.com/ugd/32acb1_8918c0dc561a491fa83685ac52d9004d.pdf
    • https://static.usrfiles.com/ugd/b8c837_0386f3b8c84d4403ae92a649a43a33dc.pdf
    • https://cdn.shopify.com/s/files/1/0468/0689/2695/files/zajuzokuvenikox.pdf
    • https://cdn.shopify.com/s/files/1/0431/8127/7342/files/gowetimukomejeda.pdf
    • https://cdn.shopify.com/s/files/1/0435/4523/1515/files/72451442608.pdf
    • https://cdn.shopify.com/s/files/1/0431/6663/0037/files/fetegegubovotume.pdf
    • https://cdn.shopify.com/s/files/1/0427/7754/2823/files/56232383263.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006526.bin
bbb3a0c087a5ba9bee930973358d39303bca2b9e5b96ef29f58d77d31e3ddf4e
pdf-font-stream PDF embedded font (sfnt) at offset 0x6526 4864 bytes
font_01_sfnt_off000075dc.bin
8c9f3e2632f7391901d49b843e3f72988d7548af1a4cabbaeabd8e31b5a4746e
pdf-font-stream PDF embedded font (sfnt) at offset 0x75DC 10560 bytes