Malicious PDF — malware analysis report

Static analysis result for SHA-256 dbaa5dc9b383cabf…

MALICIOUS

PDF

46.0 KB Created: 2020-08-31 18:02:49 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 052088dbade2d223e1e54a168ba45762 SHA-1: 2a0451b38c42380466ec053385fb1620a0009346 SHA-256: dbaa5dc9b383cabfc31da19a45ea94a6bf6f6e026dbf60fd351de2ff6a64a679
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link, which is also present in the document body. This link, 'https://ttraff.me/pify?keyword=children%2527+s+songs+in+tamil+film', is designed to lead users to malicious content under the guise of relevant search results. The PDF also exhibits characteristics of a link farm, with numerous embedded links, many pointing to static.usrfiles.com. The ML classifier strongly supports the malicious nature of this PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.me/pify?keyword=children%2527+s+songs+in+tamil+film
    • https://static.usrfiles.com/ugd/0286dd_bcf60fd6f96b40629712fef40687ce35.pdf
    • https://static.usrfiles.com/ugd/136d07_4c5e4e309d8647f1ba560781253ecfd6.pdf
    • https://static.usrfiles.com/ugd/4d935e_19f23f3059774170945d1aed65f9a0df.pdf
    • https://static.usrfiles.com/ugd/b8c837_d21579b3702248fe8052b3cb6aa524ed.pdf
    • https://cdn.shopify.com/s/files/1/0428/4284/9446/files/vobifoxexunu.pdf
    • https://cdn.shopify.com/s/files/1/0428/5680/8615/files/vefera.pdf
    • https://cdn.shopify.com/s/files/1/0427/8996/1884/files/35840901693.pdf
    • https://static.usrfiles.com/ugd/e2b09b_245447ddd926400cac55e69f14a76106.pdf
    • https://static.usrfiles.com/ugd/a64c8c_6e49c68da112418898058d7c2274a522.pdf
    • https://static.usrfiles.com/ugd/b8c837_15d07be157fe4f33a5c57525b4b25485.pdf
    • https://static.usrfiles.com/ugd/625844_6775934bc6964c198ec853848726c442.pdf
    • https://static.usrfiles.com/ugd/b42fd6_bb140f2868c440669ee3be0a88ae59dd.pdf
    • https://cdn.shopify.com/s/files/1/0429/0517/4179/files/fitogizokijofoxusotufir.pdf
    • https://cdn.shopify.com/s/files/1/0428/8957/6601/files/23027853094.pdf
    • https://cdn.shopify.com/s/files/1/0437/2873/2314/files/jubofateliboditiru.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000053f1.bin
f41da3ea2d17856c60096a3844701d0b72837c776f1a07888f4a124febfc3c7b
pdf-font-stream PDF embedded font (sfnt) at offset 0x53F1 5260 bytes
font_01_sfnt_off000065a6.bin
004c2f389dd869827c34df742a3ee9152e5e5ac46e5545433eaeba61a7fe7251
pdf-font-stream PDF embedded font (sfnt) at offset 0x65A6 15712 bytes
font_02_sfnt_off00008a12.bin
1544f3b1145e6e2ee9717a4b139374b89b366991ab78571e08c6e345682b1484
pdf-font-stream PDF embedded font (sfnt) at offset 0x8A12 9560 bytes