Malicious PDF — malware analysis report

Static analysis result for SHA-256 58a8e4225005ee45…

MALICIOUS

PDF

51.4 KB Created: 2020-09-11 23:45:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: d8c0fdf181ca8df1110217fec18c6924 SHA-1: 09f34fa6925b15f2d02fb390bfbab32d560f57e4 SHA-256: 58a8e4225005ee458913f8b8d37ff02ca559d2d7f3ac4dac9240b43d87a00520
160 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF contains a lure related to a 'calculator vault' and embeds multiple links, one of which, https://ttraff.me/pify?keyword=calculator+vault+for+android+free, is flagged as a malicious redirector. The heuristic 'SE_PAYMENT_REDIRECT_LURE' further indicates a business-email-compromise pattern. The document body, though heavily obfuscated, contains the same URL, reinforcing the malicious intent to redirect the user. No scripts were extracted, limiting the analysis of further payload execution.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Payment redirection / bank-detail change lure high SE_PAYMENT_REDIRECT_LURE
    Document describes new or changed bank, wire, ACH, IBAN, SWIFT, or routing instructions — a high-value business-email-compromise pattern
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/pify?keyword=calculator+vault+for+android+free
    • http://torusaj.genesistimetobegin.com/uploads/1/3/1/4/131453181/ef752c94196e89.pdf
    • https://static.usrfiles.com/ugd/913720_6f7fc065ab9e4036aba571f186e004d5.pdf
    • https://static.usrfiles.com/ugd/70094d_a3fcbbf8f1b943f5b9eee0be91c26535.pdf
    • https://static.usrfiles.com/ugd/50988c_ce57e37649b04ec38b8e8ccfdcd4feca.pdf
    • https://static.usrfiles.com/ugd/f0e51d_933fc87b4fd84c6daecb5ef33e87eff2.pdf
    • https://static.usrfiles.com/ugd/24d943_2514ac4a2a314b6aa0fc56f2f87f0378.pdf
    • https://cdn.shopify.com/s/files/1/0429/9482/7415/files/ishihara_color_blind_test_book.pdf
    • https://cdn.shopify.com/s/files/1/0434/1989/3927/files/dd_form_1907.pdf
    • https://cdn.shopify.com/s/files/1/0430/3287/1074/files/discipleship_bible_study_lessons.pdf
    • https://static.usrfiles.com/ugd/b8c837_e7f2821b128948499859d5dc8850d0dc.pdf
    • https://static.usrfiles.com/ugd/4bdc6d_69e5930259c441faac6bad1c95e51a34.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006c28.bin
8d36c8a1cca932b946d10a2d403f01a492adb146355fd17f1e49ee0e763fee4d
pdf-font-stream PDF embedded font (sfnt) at offset 0x6C28 4804 bytes
font_01_sfnt_off00007c89.bin
0df9832cfc5af80b801f03965aa32ffa143350b02011ec55e095d3f91a351c64
pdf-font-stream PDF embedded font (sfnt) at offset 0x7C89 2012 bytes
font_02_sfnt_off000085bf.bin
b03f595802a22d886c006d3b74d26ccf165766d5e1cd145c8ba54caa5804ce3f
pdf-font-stream PDF embedded font (sfnt) at offset 0x85BF 10516 bytes
font_03_sfnt_off0000a9e3.bin
1982e3e1b027e8782157cf04a5aa67d06f10055076cafd50740dc4fb44fafe67
pdf-font-stream PDF embedded font (sfnt) at offset 0xA9E3 16664 bytes