Malicious PDF — malware analysis report

Static analysis result for SHA-256 79d1b266aa1a7abd…

MALICIOUS

PDF

40.6 KB Created: 2020-08-14 05:01:47 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 700459ef618678204ff4cc0f93ae0737 SHA-1: 4669ba23e71473e903949f994c50fececa259ed0 SHA-256: 79d1b266aa1a7abd7fc55789ba36dfb894bde70bf7b579e97bf79dbb96766f26
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a large number of embedded links, many of which point to benign-looking Shopify URLs, but one critical link redirects to a known malicious domain, ttraff.com. This indicates a link farm or SEO poisoning attack designed to lure users to malicious infrastructure. The document body, though heavily obfuscated, contains the string 'Google assistant for windows' and the malicious redirector URL, suggesting a social engineering pretext for the malicious link. The presence of a 'download button' heuristic further supports the lure-based attack pattern.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=google+assistant++for+windows
    • http://files.santabarbarabirthmatters.com/uploads/1/3/1/0/131070151/906310182465.pdf
    • http://files.pigmentsolution.de/uploads/1/3/0/8/130874422/7490433.pdf
    • http://files.newconnectionsmetrodc.com/uploads/1/3/0/7/130776645/59d09d4b54c2c.pdf
    • http://gikoxun.406flies.com/uploads/1/3/0/7/130739173/figerafelusujej.pdf
    • https://cdn.shopify.com/s/files/1/0432/5202/3458/files/application_of_binary_search_tree_in_data_structure.pdf
    • https://cdn.shopify.com/s/files/1/0429/2853/7753/files/tejawuret.pdf
    • https://cdn.shopify.com/s/files/1/0432/5936/3488/files/piroluzut.pdf
    • https://cdn.shopify.com/s/files/1/0436/5392/2981/files/xijazumodu.pdf
    • https://cdn.shopify.com/s/files/1/0434/7258/4861/files/working_environment.pdf
    • https://cdn.shopify.com/s/files/1/0433/2548/9320/files/96133600079.pdf
    • https://cdn.shopify.com/s/files/1/0454/4213/8262/files/skywatch_tv_guide_nz.pdf
    • https://cdn.shopify.com/s/files/1/0435/9425/2456/files/9533650287.pdf
    • https://cdn.shopify.com/s/files/1/0432/0428/0481/files/gmat_analytical_writing.pdf
    • https://cdn.shopify.com/s/files/1/0431/4287/3249/files/zugub.pdf
    • https://cdn.shopify.com/s/files/1/0427/7485/5846/files/17660105166.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006048.bin
b96c907469881de13d92c68b8a9f4365325b38ac6a3ab3c7ec8e8ac27a9b6772
pdf-font-stream PDF embedded font (sfnt) at offset 0x6048 5200 bytes
font_01_sfnt_off00007218.bin
8af1e2ef35ee5e9626906779e355ea221cd00aee7fc0320d37f0b3f5271a7c00
pdf-font-stream PDF embedded font (sfnt) at offset 0x7218 10428 bytes