Malicious PDF — malware analysis report

Static analysis result for SHA-256 19e728d42d54a17e…

MALICIOUS

PDF

51.6 KB Created: 2020-08-17 04:59:58 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b56437206444a989ed2a276c9c5e69ac SHA-1: 73e40580ed7f610160dc43d6cdc5f33f9e497508 SHA-256: 19e728d42d54a17e65ff08b2c68b33f906d59bfd9ccbb5e3410fbdc84e990b7e
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.com/pify?keyword=listeria+monocytogenes+characteristics+pdf'. This URL is presented within the document body, disguised as a search result for a seemingly legitimate topic. The file also exhibits characteristics of a link farm, with numerous embedded URLs, many pointing to benign content on Shopify, likely to obscure the malicious redirector. The primary intent appears to be luring the user to click the malicious link, which is a common social engineering tactic.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=listeria+monocytogenes+characteristics+pdf
    • http://simop.tpched.org/uploads/1/3/0/7/130739602/2f330602ca94.pdf
    • https://cdn.shopify.com/s/files/1/0432/3196/9438/files/the_beatles_help_sheet_music.pdf
    • https://cdn.shopify.com/s/files/1/0427/4506/9724/files/73370600328.pdf
    • https://cdn.shopify.com/s/files/1/0435/8524/1256/files/gorobutiguvonozi.pdf
    • https://cdn.shopify.com/s/files/1/0432/5870/8136/files/hypertension_guideline_2017.pdf
    • https://cdn.shopify.com/s/files/1/0434/6223/0181/files/wipetufobijajujasopen.pdf
    • https://cdn.shopify.com/s/files/1/0431/4847/6572/files/aircraft_structural_design.pdf
    • https://cdn.shopify.com/s/files/1/0449/9750/9278/files/fundamental_of_accounting_principles_21st_edition.pdf
    • https://cdn.shopify.com/s/files/1/0434/6091/9461/files/vehicle_blackbox_dvr_manual.pdf
    • https://cdn.shopify.com/s/files/1/0428/5654/6467/files/vejemibutefonok.pdf
    • https://cdn.shopify.com/s/files/1/0431/8799/4792/files/89630316916.pdf
    • https://cdn.shopify.com/s/files/1/0429/6212/4959/files/90829702988.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000079ab.bin
cd6fe4f9bf2c2bfdd52920bd8e02a90e23c3ec2c869c4574f1d0e029e87eecd9
pdf-font-stream PDF embedded font (sfnt) at offset 0x79AB 5580 bytes
font_01_sfnt_off00008c6f.bin
0b38f6fd5e0b54bfa22d5adee1cfe00629fe134100fc7cfc1ad14a2ab7974207
pdf-font-stream PDF embedded font (sfnt) at offset 0x8C6F 6148 bytes
font_02_sfnt_off00009c4f.bin
b7dff752fe2d81c68952aa79d3452329028e25034062dd55d8d06d5459522a8c
pdf-font-stream PDF embedded font (sfnt) at offset 0x9C4F 10816 bytes