Malicious PDF — malware analysis report

Static analysis result for SHA-256 183dafe69891d44d…

MALICIOUS

PDF

60.1 KB Created: 2020-07-30 18:13:45 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b67b45912f10487164b03a86e34a613a SHA-1: 1b863021ba576be863c88ec258a6c58f4217072e SHA-256: 183dafe69891d44d2e4bba92b26cc2c014bcb9ac1fb53aa2d7aaebc9acb50e08
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links, many of which point to redirector infrastructure or unknown domains, suggesting a link farm or phishing campaign. The ML classifier also strongly indicated maliciousness. While no scripts were directly extracted, the PDF structure and embedded links are indicative of a malicious document designed to lead users to harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=nips+2020+accepted+papers+pdf
    • http://files.bozhenaevanstherapy.com/uploads/1/3/1/1/131163780/303727.pdf
    • http://files.vancouver604.ca/uploads/1/3/0/7/130740249/kelufozizilage-jorolujibevaken-digujezoje-kojotekikonep.pdf
    • http://files.pixiedustmagictravel.com/uploads/1/3/2/6/132681440/7f5119fab91.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0438/7491/0376/files/99549054025.pdf
    • https://cdn.shopify.com/s/files/1/0433/0445/2246/files/jojuwowupijitagina.pdf
    • https://cdn.shopify.com/s/files/1/0437/3417/1800/files/womomolamelubaserobuto.pdf
    • https://cdn.shopify.com/s/files/1/0436/6453/9798/files/4682342232.pdf
    • https://cdn.shopify.com/s/files/1/0429/5059/0627/files/junafutorikabikafajazet.pdf
    • https://cdn.shopify.com/s/files/1/0428/9835/8432/files/27392185694.pdf
    • https://cdn.shopify.com/s/files/1/0435/5106/4228/files/62470444712.pdf
    • https://cdn.shopify.com/s/files/1/0439/1721/3851/files/muriwurim.pdf
    • https://cdn.shopify.com/s/files/1/0429/7375/7603/files/22752384374.pdf
    • https://cdn.shopify.com/s/files/1/0434/3224/7457/files/soporagixalari.pdf
    • https://cdn.shopify.com/s/files/1/0437/0232/1307/files/85944396035.pdf
    • https://cdn.shopify.com/s/files/1/0431/2639/0946/files/firezunimekufuvudif.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000a1ea.bin
a9862c57a6e794d43429cb9f42cdd9e5a04a1764bbbf422be5d4d554463abbe5
pdf-font-stream PDF embedded font (sfnt) at offset 0xA1EA 4932 bytes
font_01_sfnt_off0000b2bb.bin
b09cbe3f3ce6de6006aa358ffe1fb41e50696d5d6c5b6aa039be5598cb3d4138
pdf-font-stream PDF embedded font (sfnt) at offset 0xB2BB 15668 bytes