Malicious PDF — malware analysis report

Static analysis result for SHA-256 a20c3c0e94d0f7d4…

MALICIOUS

PDF

50.6 KB Created: 2020-08-30 20:24:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b644557beb892e5fea45a915bd54c606 SHA-1: c8e8bb4cbd3dff4848be40770836260149b9e0ac SHA-256: a20c3c0e94d0f7d4b8ad437f91ed1dead5fa4f835cfb1ba801f8f3f7c01b40f2
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1059.001 Command and Scripting Interpreter: PowerShell

The PDF contains a link to a known malicious redirector, disguised with a keyword related to song downloads. The ML classifier strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains the same malicious URL, suggesting the primary intent is to redirect the user to a harmful site.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=tu+tu+hai+wahi+song+mp3+download
    • https://static.usrfiles.com/ugd/60933b_58d7bc957eb745b58fdbcd5a0e17ef45.pdf
    • https://static.usrfiles.com/ugd/b8c837_529e85e8eafa4c27acd767bef33f89b5.pdf
    • https://static.usrfiles.com/ugd/b11f6d_6a5eaa1fc14f4b1999e6f27d749ddd4f.pdf
    • https://static.usrfiles.com/ugd/f55bec_babb88a5f6ee4c339e8c5eab3a2ac2f1.pdf
    • https://static.usrfiles.com/ugd/b8c837_f597cbd6716a4d549b8655d98ca9ebd9.pdf
    • https://static.usrfiles.com/ugd/b8c837_03eac66e30104d518342abf41c340fb7.pdf
    • https://static.usrfiles.com/ugd/912de2_1a4b93844a694c91bd4c63fdb68d03ae.pdf
    • https://static.usrfiles.com/ugd/7dd30d_9ffa43f7334745758fde02df6edd935a.pdf
    • https://cdn.shopify.com/s/files/1/0429/0006/2371/files/pifanusimasiruxilaviw.pdf
    • https://cdn.shopify.com/s/files/1/0460/9182/9412/files/vepugotalimulorazir.pdf
    • https://cdn.shopify.com/s/files/1/0430/4742/0066/files/dowigigusowusiwejaweli.pdf
    • https://cdn.shopify.com/s/files/1/0435/4323/2661/files/sql_interview_questions_for_experience.pdf
    • https://static.usrfiles.com/ugd/f0f215_e011ce0e636d4d9eb485334a908e5c96.pdf
    • https://static.usrfiles.com/ugd/b8c837_b100a3be4a034c869ea71974aaa80930.pdf
    • https://static.usrfiles.com/ugd/a91264_3d66e6a2b1124606936e2579eccb4983.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005151.bin
231502062b883a111c844fabc35975a13610baa5c50e96d58f6efbf2a9afdfe2
pdf-font-stream PDF embedded font (sfnt) at offset 0x5151 5484 bytes
font_01_sfnt_off000063de.bin
a1dedc3931fbca03c9b8a70164579be921c546209591819cec09e3cd28e33465
pdf-font-stream PDF embedded font (sfnt) at offset 0x63DE 14716 bytes
font_02_sfnt_off00009184.bin
e58e8e8d3617fa2f52d62469859eb662c26c1c1537dc21f5cc6f1aa71eaa6aed
pdf-font-stream PDF embedded font (sfnt) at offset 0x9184 18776 bytes
font_03_sfnt_off0000af27.bin
5d9ebd0351c6bcac14c1f3074ca9379133139a603f1cc4358b7c92d10e4f4759
pdf-font-stream PDF embedded font (sfnt) at offset 0xAF27 2900 bytes