Malicious PDF — malware analysis report

Static analysis result for SHA-256 50b9e65a4ed64360…

MALICIOUS

PDF

59.8 KB Created: 2020-08-09 04:42:11 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 9d7fd4c533c804f84cab5d66ba60e4c5 SHA-1: c594e3e543c447bbac73d0cf2151e817eb83d223 SHA-256: 50b9e65a4ed6436017bef1e7bbdc5959da20eed85e85b6442dbe5997958b76f3
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains numerous external links, with one identified as a malicious redirector. The document body, though heavily obfuscated, contains the string 'Angelus latin pdf' and the malicious URL, suggesting a lure to a phishing or malware distribution site. The presence of a PDF link farm heuristic further supports the malicious intent of distributing links to external sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=angelus+latin+pdf
    • http://files.laurarichardsphotography.com/uploads/1/3/0/7/130776388/wizepabafis-fizelopixagoduv.pdf
    • http://files.caryyurkiw.com/uploads/1/3/1/4/131483002/2236a6624.pdf
    • http://files.newerabulldogges.com/uploads/1/3/0/8/130873846/4447128.pdf
    • http://files.senmurvconsulting.com/uploads/1/3/1/4/131407357/8468836.pdf
    • https://cdn.shopify.com/s/files/1/0429/9515/5105/files/jamugifomobaxin.pdf
    • https://cdn.shopify.com/s/files/1/0431/5496/4637/files/kesigurupoponejef.pdf
    • https://cdn.shopify.com/s/files/1/0438/0724/4450/files/47141207480.pdf
    • https://cdn.shopify.com/s/files/1/0432/3049/4882/files/lukixifazaluner.pdf
    • https://cdn.shopify.com/s/files/1/0435/2576/7320/files/holland_code_careers_list.pdf
    • https://cdn.shopify.com/s/files/1/0434/6193/5261/files/85347433198.pdf
    • https://cdn.shopify.com/s/files/1/0439/8402/7806/files/xesadarapax.pdf
    • https://cdn.shopify.com/s/files/1/0430/4722/3458/files/59536454431.pdf
    • https://cdn.shopify.com/s/files/1/0434/7658/2552/files/22199756862.pdf
    • https://cdn.shopify.com/s/files/1/0440/1420/7134/files/11948860281.pdf
    • https://cdn.shopify.com/s/files/1/0432/9704/6696/files/18837138466.pdf
    • https://cdn.shopify.com/s/files/1/0434/9375/2997/files/93828666237.pdf
    • https://cdn.shopify.com/s/files/1/0431/8858/4605/files/berlitz_english_level_4_book.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000095c0.bin
e66bd3b0cadd51d10c38de2917a1c7065ce3f794fd42d5b376bcffec40b5dcd7
pdf-font-stream PDF embedded font (sfnt) at offset 0x95C0 5100 bytes
font_01_sfnt_off0000a73d.bin
fa10b0b3f4ed3a9d8ba595538a26907cedf38be382c7dabe9e7b785fc802ac8a
pdf-font-stream PDF embedded font (sfnt) at offset 0xA73D 10824 bytes
font_02_sfnt_off0000cc2a.bin
aac191dbdc9994f81ee36cdb7aa02588057de365a32a570fbe93e7c08ea48a46
pdf-font-stream PDF embedded font (sfnt) at offset 0xCC2A 16300 bytes