Malicious PDF — malware analysis report

Static analysis result for SHA-256 2a1dfbd538c7ac40…

MALICIOUS

PDF

43.3 KB Created: 2020-08-06 10:01:38 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 7e8ef063bc87cfb3dedf57af2fb537f0 SHA-1: e07854511bc019d39f81b53215186f10ebccdae5 SHA-256: 2a1dfbd538c7ac408d447f50b27a3cf5edc651b13e6a6e996ece60f6c6aa9613
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF file contains a lure related to payment authorization and embeds numerous links. One critical heuristic identified a link to a known malicious redirector at `https://ttraff.cc/pify?keyword=recurring+payment+authorization+form+pdf`. Another heuristic indicates a link farm, with many links pointing to Shopify domains, likely for SEO poisoning or to host further malicious content. The document body, though partially corrupted, also contains the malicious URL and references to payment forms, reinforcing the lure. No scripts were extracted from this sample.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=recurring+payment+authorization+form+pdf
    • http://files.bviolinsltd.com/uploads/1/3/1/4/131453651/f2a8d71ae5.pdf
    • http://files.artfulconnextions.com/uploads/1/3/0/8/130815381/c226f336ee0ba31.pdf
    • http://files.newjerseyparaunityexpo.com/uploads/1/3/1/6/131606186/4192326.pdf
    • http://files.swinger-symbol.com/uploads/1/3/1/8/131856852/kofam_lajizu.pdf
    • https://cdn.shopify.com/s/files/1/0432/3917/8399/files/86713653112.pdf
    • https://cdn.shopify.com/s/files/1/0435/7862/2111/files/free_english_grammar_book_1.pdf
    • https://cdn.shopify.com/s/files/1/0435/6990/5825/files/barreras_administrativas_de_la_comunicacion.pdf
    • https://cdn.shopify.com/s/files/1/0436/6961/8841/files/4406845601.pdf
    • https://cdn.shopify.com/s/files/1/0429/1005/6615/files/18555917967.pdf
    • https://cdn.shopify.com/s/files/1/0449/6778/8712/files/antrenmanlarla_matematik_2_zml.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/89462818099.pdf
    • https://cdn.shopify.com/s/files/1/0432/9324/5590/files/rapid_gator._net_premium_account_generator.pdf
    • https://cdn.shopify.com/s/files/1/0435/9992/1315/files/31033140833.pdf
    • https://cdn.shopify.com/s/files/1/0438/9906/0376/files/59495133102.pdf
    • https://cdn.shopify.com/s/files/1/0431/0876/1764/files/xadif.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006b15.bin
2b0f85a23f369c9c2dcf848c39bda30f66101d08a80a2a1562d2d40d3c2ede2b
pdf-font-stream PDF embedded font (sfnt) at offset 0x6B15 5516 bytes
font_01_sfnt_off00007dc5.bin
ce135466d7bf60c537c6129430fd040219a9e2a47fd150d8fb8e11c91a3acebf
pdf-font-stream PDF embedded font (sfnt) at offset 0x7DC5 10372 bytes