Malicious PDF — malware analysis report

Static analysis result for SHA-256 daa9b615c8ccb7d2…

MALICIOUS

PDF

41.9 KB Created: 2020-09-04 17:10:27 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: a5772d304905ac812838cde45b02cbd5 SHA-1: e20818b534a7737dd1f16864cc52e5e1fd783a41 SHA-256: daa9b615c8ccb7d2141c7ef816d49fffa9806ac7e744d09f83cdb66ca3557fe5
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a heuristic firing for PDF_MALICIOUS_REDIRECTOR_LINK, indicating a link to malicious infrastructure. The document body, though heavily obfuscated, contains the text 'Army song video status' and the malicious URL 'https://ttraff.club/wix?keyword=army+song+video+status'. This suggests the document is designed to trick users into clicking the link, likely leading to further malicious content or downloads. The presence of numerous other PDF links, flagged by PDF_SEO_LINK_FARM, further supports a content-luring or SEO-poisoning attack vector.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=army+song+video+status
    • https://cdn.shopify.com/s/files/1/0456/9143/7215/files/dls_2019_profile_dat_hack.pdf
    • https://cdn.shopify.com/s/files/1/0447/8281/3341/files/finogimi.pdf
    • https://cdn.shopify.com/s/files/1/0428/8276/0870/files/47228090597.pdf
    • https://cdn.shopify.com/s/files/1/0431/9641/6157/files/60064751170.pdf
    • https://cdn.shopify.com/s/files/1/0433/8860/0478/files/80688905542.pdf
    • https://cdn.shopify.com/s/files/1/0437/6186/0757/files/2020_buick_envision_owners_manual.pdf
    • https://cdn.shopify.com/s/files/1/0437/7745/8334/files/abdominal_bracing_exercises.pdf
    • https://cdn.shopify.com/s/files/1/0429/5314/6517/files/41468157016.pdf
    • https://cdn.shopify.com/s/files/1/0429/7916/4314/files/beholder_android_apk.pdf
    • https://cdn.shopify.com/s/files/1/0429/6713/8470/files/alimentacion_en_el_tercer_trimestre_de_embarazo.pdf
    • https://cdn.shopify.com/s/files/1/0438/0337/7824/files/xubipaxusoxu.pdf
    • https://cdn.shopify.com/s/files/1/0431/9051/7911/files/hermeneutica_del_sujeto_la_piqueta.pdf
    • https://cdn.shopify.com/s/files/1/0448/9995/8939/files/supercalifragilisticexpialidocious_broadway_sheet_music.pdf
    • https://cdn.shopify.com/s/files/1/0432/6244/3683/files/79361350753.pdf
    • https://cdn.shopify.com/s/files/1/0435/7629/5592/files/48594308228.pdf
    • https://cdn.shopify.com/s/files/1/0428/7509/3159/files/lamegubux.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000057a4.bin
71222559b2bdf716cd7a3b5fcb0a6f44017b1c3b663667b259e4831b0bc4001e
pdf-font-stream PDF embedded font (sfnt) at offset 0x57A4 5264 bytes
font_01_sfnt_off00006982.bin
ba7cf07fa51b1ac4c0c75007dc7ea2810d66e9c39cbe242aa07e109c27e90a55
pdf-font-stream PDF embedded font (sfnt) at offset 0x6982 10248 bytes
font_02_sfnt_off00008ca1.bin
cc0078d224071541c69018a17d8897294fd9eadeb00e331f74482393d329c90b
pdf-font-stream PDF embedded font (sfnt) at offset 0x8CA1 3572 bytes