Malicious PDF — malware analysis report

Static analysis result for SHA-256 972345ab30bca40d…

MALICIOUS

PDF

560.3 KB Created: 2020-09-18 09:27:56 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 2443eb2867c94666b4f47257eb255b0d SHA-1: bb0e5361202757e9a0693ec2855582d3df15fbe0 SHA-256: 972345ab30bca40d5e6e1d584768fcae7477fb2d8ca538a0e8cdc65edce31000
130 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains heuristics indicating it is a malicious redirector link and uses lures consistent with advance-fee scams and callback phishing. The embedded URL, https://ttraff.com/pify?keyword=daniel+yeager+travel+center, is flagged as malicious. The document body, though heavily obfuscated, contains fragments of the malicious URL and text related to a travel center, reinforcing the lure.

Heuristics 5

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=daniel+yeager+travel+center
    • https://d3c25956-3100-4bed-a4af-3b5222360d5c.filesusr.com/ugd/b28ae2_ed3ec5e6dbd74e0a8336bfebdc875104.pdf?index=true
    • https://fe566b67-1d1c-40f1-b358-b939baa29969.filesusr.com/ugd/f34823_e22d103025a3471586523197f919d462.pdf?index=true
    • https://c9b2b24e-9df5-408e-92d9-56977e0db45a.filesusr.com/ugd/2ca22b_d301435d3c5845cbb8dc00518b68e912.pdf?index=true
    • https://12eb357d-75cc-494a-a942-3a33f3142d3b.filesusr.com/ugd/8a419d_2dfdcde3de4e4670a800c06b13f5e130.pdf?index=true
    • https://43b9ac65-16c6-43cf-be9a-c8e9524ec387.filesusr.com/ugd/6d59ab_7d262b34c6a44a839542a130e6b5dafe.pdf?index=true
    • https://b951aa38-c8dd-415a-a7e7-8e6b3d060ca9.filesusr.com/ugd/c844bf_fb847eda52f047e6ba0e3fcd6c6e1cba.pdf?index=true
    • https://3750bf62-1e46-417f-9462-e5f0546229e9.filesusr.com/ugd/105a8c_16d45df465784c929d311f2f95513ee7.pdf?index=true
    • https://cdn.shopify.com/s/files/1/0433/4508/4574/files/69878904867.pdf
    • https://cdn.shopify.com/s/files/1/0434/5970/7037/files/indiana_new_hire_reporting.pdf
    • https://cdn.shopify.com/s/files/1/0437/2866/6785/files/delijene.pdf
    • https://cdn.shopify.com/s/files/1/0431/6938/2568/files/the_radical_reformation_the_anabaptists.pdf
    • https://cdn.shopify.com/s/files/1/0431/0607/4780/files/avast_antivirus_setup_file_for_pc.pdf
    • https://cdn.shopify.com/s/files/1/0438/2402/1664/files/libro_de_ingles_achievers_b1.pdf
    • https://cdn.shopify.com/s/files/1/0437/9885/5840/files/genetic_engineering_and_biotechnology.pdf
    • https://cdn.shopify.com/s/files/1/0437/1624/7703/files/dudilivesululokojiliri.pdf
    • https://cdn.shopify.com/s/files/1/0432/5225/2829/files/zapofogo.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/50537202024.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00086a1c.bin
4a9acf6e4b3ad93a673ab4b4ccad74b7087e4f5c7e50eea543c8db835048f935
pdf-font-stream PDF embedded font (sfnt) at offset 0x86A1C 4948 bytes
font_01_sfnt_off00087b2a.bin
0b3c09e9ae413aef8932d9eb72fa8d93627b0146c6123def1c6499446df5a58a
pdf-font-stream PDF embedded font (sfnt) at offset 0x87B2A 16304 bytes