Malicious PDF — malware analysis report

Static analysis result for SHA-256 58be7189052cf5b9…

MALICIOUS

PDF

45.0 KB Created: 2020-08-31 01:03:04 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 3811069c39f0812897c2b41c61ccc8f4 SHA-1: f370a4cc84cf40a5a941775e2e7322ccca86d7cc SHA-256: 58be7189052cf5b972a81c49ab31b2ab05b706964b10eaf5b662a393d412d6b4
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a mass of external links, with the primary link pointing to a known malicious redirector. The document body, though heavily obfuscated, contains text related to 'urban legend ti free download' and the authoring application, suggesting a lure to entice users to click the malicious link. The ML classifier strongly flagged this PDF as malicious, supporting the conclusion that it is designed for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=urban+legend+ti+free+download
    • https://static.usrfiles.com/ugd/7dd30d_43fe1a7b3bc9400e9779477f7783a544.pdf
    • https://static.usrfiles.com/ugd/b8c837_808dcbcd55bd42d580d2a6857c57554a.pdf
    • https://static.usrfiles.com/ugd/b4609a_288037bec8714e0db297e2047ef3307c.pdf
    • https://static.usrfiles.com/ugd/6d59ab_8714a41ca22f46aab77868f53d6c4853.pdf
    • https://static.usrfiles.com/ugd/0049ca_4c56ba0764b8460792dd8aa06e74fa09.pdf
    • https://static.usrfiles.com/ugd/299074_371d0a106c9a459aaf904a182e9a9a71.pdf
    • https://cdn.shopify.com/s/files/1/0434/0839/2353/files/wewejumeveviror.pdf
    • https://cdn.shopify.com/s/files/1/0437/8856/6677/files/net_framework_version_2._0._5072_free.pdf
    • https://cdn.shopify.com/s/files/1/0431/6856/3355/files/59258643611.pdf
    • https://cdn.shopify.com/s/files/1/0461/1817/4884/files/989021388.pdf
    • https://cdn.shopify.com/s/files/1/0432/5913/4112/files/pdf_to_word_converter_download_crack.pdf
    • https://cdn.shopify.com/s/files/1/0430/7176/6690/files/85713856937.pdf
    • https://cdn.shopify.com/s/files/1/0435/1682/1672/files/adverb_clause_practice.pdf
    • https://cdn.shopify.com/s/files/1/0430/8625/0137/files/69574153709.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004a68.bin
3888ce4cc2f452c67150f3ac28f3d691c527724ac7ba4c87af8581d53e26fef1
pdf-font-stream PDF embedded font (sfnt) at offset 0x4A68 12056 bytes
font_01_sfnt_off00007157.bin
be61194653ef4a0cdf77a5ff8f8f5a426ca06b543c42b9fa185895e87fd65a64
pdf-font-stream PDF embedded font (sfnt) at offset 0x7157 5120 bytes
font_02_sfnt_off000082de.bin
8f96f8ea2f8f4b054c311ebb2d0af5b9a6fc08b14d586d46b742995b89409006
pdf-font-stream PDF embedded font (sfnt) at offset 0x82DE 10592 bytes