Malicious PDF — malware analysis report

Static analysis result for SHA-256 df3476fe5eaf782a…

MALICIOUS

PDF

40.4 KB Created: 2020-08-14 05:40:21 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 6fadc5c3ac664c1f0a2c3dea527f686b SHA-1: 220644a52183d443c79c2e77a334225281c3f103 SHA-256: df3476fe5eaf782aab97574541f89f6fd50f26b033c4a7b1ba2c7a31addc9da4
128 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious Link

The PDF file contains a "simple receipt of payment template" lure, as indicated by the document body and heuristic firings. It embeds numerous links, with a critical finding being a redirector link to `https://ttraff.cc/pify?keyword=simple+receipt+of+payment+template`. This suggests the document's primary purpose is to redirect users to malicious infrastructure, likely for phishing or to download further malware. The presence of many external PDF links, including to Shopify domains, indicates a link farm strategy to improve search engine visibility for malicious content.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=simple+receipt+of+payment+template
    • http://files.helenaeloisephotography.com/uploads/1/3/1/8/131871585/xijoxukowowifiw_busos.pdf
    • http://files.pilatesdonewright.com/uploads/1/3/1/4/131453592/rumemasirofosog.pdf
    • http://files.thepetalpatch.com/uploads/1/3/1/4/131407705/silebe.pdf
    • http://burib.mlledowding.com/uploads/1/3/1/4/131407089/5865922.pdf
    • http://files.enfuro.nl/uploads/1/3/1/8/131856330/beveponiminatif.pdf
    • https://cdn.shopify.com/s/files/1/0447/9827/9841/files/fedex_international_waybill.pdf
    • https://cdn.shopify.com/s/files/1/0436/4579/6512/files/verubuvebobu.pdf
    • https://cdn.shopify.com/s/files/1/0449/8610/6014/files/65504353957.pdf
    • https://cdn.shopify.com/s/files/1/0439/6895/4526/files/merriam_webster_english_dictionary.pdf
    • https://cdn.shopify.com/s/files/1/0428/5032/0543/files/xewidetisuvuvijusexilival.pdf
    • https://cdn.shopify.com/s/files/1/0428/3236/3676/files/admiral_byrd_diary.pdf
    • https://cdn.shopify.com/s/files/1/0428/2135/3635/files/1000_vocabulary_words_with_meaning_and_sentence.pdf
    • https://cdn.shopify.com/s/files/1/0435/2750/4024/files/40196299835.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/66916333827.pdf
    • https://cdn.shopify.com/s/files/1/0431/3900/6632/files/xesuzin.pdf
    • https://cdn.shopify.com/s/files/1/0430/9732/5732/files/fefapikedenatexusoxufova.pdf
    • https://cdn.shopify.com/s/files/1/0428/4976/3494/files/ganebizali.pdf
    • https://cdn.shopify.com/s/files/1/0431/3884/2779/files/52375605694.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000060cf.bin
a0b3538c0f39a8c5939fa22ff9fa4bae751d4ede0f124526303d50f1aaa27dc0
pdf-font-stream PDF embedded font (sfnt) at offset 0x60CF 5188 bytes
font_01_sfnt_off00007260.bin
bad1b563238428e49b32be68b2ed1a899cf7ce5062b827e49db740063ce6a13d
pdf-font-stream PDF embedded font (sfnt) at offset 0x7260 9960 bytes