Malicious PDF — malware analysis report

Static analysis result for SHA-256 53657c1df140b173…

MALICIOUS

PDF

45.4 KB Created: 2020-09-06 04:45:34 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: cb13c0b67547815fe808b1378ec4305d SHA-1: 5848a0497140b1161f476339f65e2dea5db67024 SHA-256: 53657c1df140b17345dfabfa7500642dc7d57566f7c26637fc20ab888f4c878a
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a lure for a job vacancy, directing the user to a malicious URL. The heuristic PDF_MALICIOUS_REDIRECTOR_LINK and the embedded URL strongly indicate a phishing attempt. The ML classifier also flagged this PDF with high confidence. No scripts were extracted, but the document body and heuristics point to a social engineering attack.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.club/wix?keyword=reporter+newspaper+ethiopia+vacancy
    • https://cdn.shopify.com/s/files/1/0434/3191/9765/files/gunabazonin.pdf
    • https://cdn.shopify.com/s/files/1/0432/6621/2003/files/xutizajadegabaru.pdf
    • https://cdn.shopify.com/s/files/1/0429/5891/3689/files/85753321880.pdf
    • https://cdn.shopify.com/s/files/1/0461/3881/8713/files/asciidoctor-_windows_install.pdf
    • https://static.usrfiles.com/ugd/04c368_d86c2d0b4e17433f8843231f6832914d.pdf
    • https://static.usrfiles.com/ugd/27135d_3ce107712eb64aa0a5f0131cb802693f.pdf
    • https://static.usrfiles.com/ugd/d4a9d6_53c7f32b37234b3caa289a7b5023cc4c.pdf
    • https://static.usrfiles.com/ugd/db93e9_c8f6850e34784c218d5eb0ff669c0c5e.pdf
    • https://static.usrfiles.com/ugd/04c368_95ac13b2fdf74719852e77d9435d10d4.pdf
    • https://static.usrfiles.com/ugd/865d50_2848d3d510cd4a5e9715457b77fcd68e.pdf
    • https://static.usrfiles.com/ugd/3e5d97_b50f5c32cf054507ac9fcffd7407d3c4.pdf
    • https://static.usrfiles.com/ugd/cd79e3_53f48a44d899491e9ea0433e2d31858f.pdf
    • https://static.usrfiles.com/ugd/b8c837_9bb36fedd0e64de69d0081b36b672f7a.pdf
    • https://static.usrfiles.com/ugd/a8c229_3c8c9d4c7cda407cb94891e92a170767.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000073e7.bin
bd4f1104d5d22f485c843839ae641e2cdc33ae458d2c1fbc58d741bb55f20a5f
pdf-font-stream PDF embedded font (sfnt) at offset 0x73E7 5248 bytes
font_01_sfnt_off000085dc.bin
8351b90cd62b7be7de7647e99ee70601bbd01bf1a9b65a2934b32b18098df6c1
pdf-font-stream PDF embedded font (sfnt) at offset 0x85DC 10164 bytes