Malicious PDF — malware analysis report

Static analysis result for SHA-256 95755d5284a61397…

MALICIOUS

PDF

45.0 KB Created: 2020-09-01 10:31:57 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5d088323c7d05608cb22fd71edaac933 SHA-1: 7cf1ed3181fe3ab117360a160c5f26fc164d2e01 SHA-256: 95755d5284a613972695b8ba87f8a1c8a34ec9320b2f4b0f8d0d88853e7a6d52
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains a lure related to 'construction cost estimate template' and embeds multiple links. One critical heuristic indicates a malicious redirector link, specifically 'https://ttraff.link/pify?keyword=construction+cost+estimate+template+word', which is designed to lead users to malicious infrastructure. Another heuristic flags the document as a link farm, with numerous external PDF links hosted on cdn.shopify.com, suggesting an attempt to manipulate search engine results or distribute further malicious content. No scripts were extracted from this sample.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/pify?keyword=construction+cost+estimate+template+word
    • https://cdn.shopify.com/s/files/1/0427/7967/2735/files/xaseru.pdf
    • https://cdn.shopify.com/s/files/1/0433/7706/6145/files/libro_cerebrito_gratis.pdf
    • https://cdn.shopify.com/s/files/1/0459/6219/9200/files/12551023607.pdf
    • https://cdn.shopify.com/s/files/1/0437/7791/7090/files/google_maps_slow_android_2019.pdf
    • https://cdn.shopify.com/s/files/1/0437/8260/2904/files/call_of_cthulhu_rpg_investigator_handbook.pdf
    • https://cdn.shopify.com/s/files/1/0435/9313/8333/files/11746774288.pdf
    • https://cdn.shopify.com/s/files/1/0430/0416/6297/files/95184040061.pdf
    • https://cdn.shopify.com/s/files/1/0434/4614/1093/files/c_pointers_tutorial.pdf
    • https://cdn.shopify.com/s/files/1/0431/5843/8037/files/kukesom.pdf
    • https://cdn.shopify.com/s/files/1/0433/4786/9850/files/adanga_maru_2018_full_movie_free.pdf
    • https://static.usrfiles.com/ugd/eda9ba_e73840c3e16c4468bee222081170f785.pdf
    • https://static.usrfiles.com/ugd/9ea91e_81d38c2547894a23814b02c5900bf424.pdf
    • https://cdn.shopify.com/s/files/1/0431/6489/3345/files/tutef.pdf
    • https://cdn.shopify.com/s/files/1/0436/5074/4478/files/6201639847.pdf
    • https://cdn.shopify.com/s/files/1/0437/4275/7013/files/yesterday_weather_report_in_bangalore.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006549.bin
219bd6b5b27fec78529bc3d7ef63411f2ecbe96f968ff32ddc419e6d37cb7bed
pdf-font-stream PDF embedded font (sfnt) at offset 0x6549 5216 bytes
font_01_sfnt_off000076fe.bin
88b17a182cf0d359044404c3e41c33eefb6999f084677ae523977733fe6041a5
pdf-font-stream PDF embedded font (sfnt) at offset 0x76FE 9964 bytes
font_02_sfnt_off00009914.bin
1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e
pdf-font-stream PDF embedded font (sfnt) at offset 0x9914 4324 bytes