Malicious PDF — malware analysis report

Static analysis result for SHA-256 79b825e4ef68d6fe…

MALICIOUS

PDF

43.4 KB Created: 2020-08-23 23:43:31 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6173636dd7357273a72aa084c4e07695 SHA-1: 458e8a154bf44ac297b8dff63c9a50db6d31ddbd SHA-256: 79b825e4ef68d6fed765ba6326cb54c77d07ec126c0bb702356ed895d7f3974f
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. Additionally, it exhibits characteristics of a PDF link farm, with numerous links hosted on Shopify, suggesting an attempt to distribute malicious content or SEO spam. The document body, though heavily obfuscated, contains the same malicious URL. The presence of a 'download button' heuristic further supports a lure-based attack pattern.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=msbte+model+answer+paper+17301+winter+2016
    • http://muwidon.axarcars.com/uploads/1/3/1/3/131378850/6ad05fdeaf5b.pdf
    • https://cdn.shopify.com/s/files/1/0435/2193/3466/files/12376680768.pdf
    • https://cdn.shopify.com/s/files/1/0439/5322/5883/files/bibuju.pdf
    • https://cdn.shopify.com/s/files/1/0437/9266/2688/files/remetuzajub.pdf
    • https://cdn.shopify.com/s/files/1/0439/1154/4987/files/bapawezelekekomusariram.pdf
    • https://cdn.shopify.com/s/files/1/0451/4558/7877/files/phantom_blade_wow.pdf
    • https://cdn.shopify.com/s/files/1/0431/2514/5760/files/lojijawakugaxa.pdf
    • https://cdn.shopify.com/s/files/1/0431/9051/7917/files/customary_international_law.pdf
    • https://cdn.shopify.com/s/files/1/0432/7217/5781/files/motagua_multipurpose_keynote_template_free.pdf
    • https://cdn.shopify.com/s/files/1/0429/0448/6055/files/sobapujarodamanitirekoban.pdf
    • https://cdn.shopify.com/s/files/1/0433/8050/6791/files/antenna_theory_analysis_and_design_3rd_edition.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/32878299647.pdf
    • https://cdn.shopify.com/s/files/1/0429/9954/6010/files/formal_definition_of_aurora_borealis.pdf
    • https://cdn.shopify.com/s/files/1/0438/0521/2832/files/70134479135.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000060dd.bin
0a9d49799b13e1a46ab4563581f230be970b4d7d4ecea5806857333c06f6d2b1
pdf-font-stream PDF embedded font (sfnt) at offset 0x60DD 6064 bytes
font_01_sfnt_off00007585.bin
bba6159b2436e7cbed0dea48e3bc972b501e023d57b689ab8ab43f9c48118ad5
pdf-font-stream PDF embedded font (sfnt) at offset 0x7585 12760 bytes