Malicious PDF — malware analysis report

Static analysis result for SHA-256 9bb2d777283a296d…

MALICIOUS

PDF

565.1 KB Created: 2020-09-03 11:26:40 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 64a5f9dae9885b27438a97d4d884f335 SHA-1: 3f562efc21627e8918cb376fc27a6419fe814b9c SHA-256: 9bb2d777283a296d59b6940dbe4ca91ad580d621f436b3a3bc22e35c005085a6
108 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains heuristics indicating it is a malicious redirector link and uses lures for advance-fee scams and fake invoices. The embedded URL, https://ttraff.com/wix?keyword=airways+nz+annual+report+2017, is flagged as malicious. The document body, though heavily obfuscated, contains the same URL, reinforcing its role as the primary lure.

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/wix?keyword=airways+nz+annual+report+2017
    • https://static.usrfiles.com/ugd/229b11_aadd433af4c948a3a692da466c2e1cd1.pdf
    • https://static.usrfiles.com/ugd/270e53_1489d7fa1e3e4fc6b5a97780e70b3938.pdf
    • https://static.usrfiles.com/ugd/c3548c_f78fd319b2b34937a2fe2cc126ba4787.pdf
    • https://static.usrfiles.com/ugd/c618e9_e4386550b2f0432fa658358f5536a509.pdf
    • https://static.usrfiles.com/ugd/95089d_6e3051805d3949838f773f00062cece5.pdf
    • https://cdn.shopify.com/s/files/1/0438/3942/2624/files/what_is_spinning_content.pdf
    • https://static.usrfiles.com/ugd/f1780b_fd83734115654407aee5c52c231cdfa6.pdf
    • https://static.usrfiles.com/ugd/b8c837_89ba8acef18a416eab540a220f16fe61.pdf
    • https://static.usrfiles.com/ugd/b8c837_46075f672294434e80e36ac09a0966c4.pdf
    • https://static.usrfiles.com/ugd/80c1db_998411814ec64aaebe7d43d8cffef0bd.pdf
    • https://static.usrfiles.com/ugd/28146e_8a22f16f53d24df69c3bb19dbc0e577f.pdf
    • https://static.usrfiles.com/ugd/b910ae_c946acf891954044a07f8888966caf91.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0008687d.bin
8378e45d034e965612be6517024fdebb78a15289890a47a82ed9ebf17a6823c5
pdf-font-stream PDF embedded font (sfnt) at offset 0x8687D 5452 bytes
font_01_sfnt_off00087b3f.bin
702ed5e10fada8c5d008e403f59bfacfac4cbb6eff5b257668c0ebb050ab54aa
pdf-font-stream PDF embedded font (sfnt) at offset 0x87B3F 16508 bytes
font_02_sfnt_off0008ae60.bin
159610043dd292fb4bb5028a4403d8c22167c620b8f957924ae8a7081a707b5c
pdf-font-stream PDF embedded font (sfnt) at offset 0x8AE60 16220 bytes