Malicious PDF — malware analysis report

Static analysis result for SHA-256 6b6ca3871fc439c8…

MALICIOUS

PDF

45.7 KB Created: 2020-08-31 21:33:28 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 181c23e8eb33831bb08ea5c9f07e4962 SHA-1: 2fce22495aaea06958c2f0db6f7df8caa0199c47 SHA-256: 6b6ca3871fc439c8188a214c3d0a8d61b116226bd141e6a0e99517f02b4d7262
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document contains a link that redirects to malicious infrastructure, disguised as an academic syllabus. The PDF is also part of a link farm, suggesting an attempt to manipulate search engine results or distribute malicious links broadly. While no scripts were explicitly extracted, the presence of embedded URLs and the ML classifier's high confidence indicate malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/wix?keyword=acca+f3+syllabus+2018+pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://cdn.shopify.com/s/files/1/0433/7650/9080/files/vosabezejijefuk.pdf
    • https://cdn.shopify.com/s/files/1/0430/0262/6202/files/voperogofupokekapadulax.pdf
    • https://cdn.shopify.com/s/files/1/0452/4494/0445/files/82026953711.pdf
    • https://cdn.shopify.com/s/files/1/0434/5892/0605/files/tibotawipufe.pdf
    • https://cdn.shopify.com/s/files/1/0432/8577/4491/files/xopuvegaren.pdf
    • https://cdn.shopify.com/s/files/1/0432/8043/3302/files/10_day_forecast_kissimmee_florida.pdf
    • https://cdn.shopify.com/s/files/1/0431/0004/5465/files/kewezidajozunovusabi.pdf
    • https://cdn.shopify.com/s/files/1/0431/0604/2023/files/munomosufapupuluvuseveri.pdf
    • https://cdn.shopify.com/s/files/1/0432/5274/4347/files/fewonarotuzi.pdf
    • https://cdn.shopify.com/s/files/1/0431/1239/9010/files/31324815085.pdf
    • https://cdn.shopify.com/s/files/1/0431/1800/2340/files/wereziluberunubewojevam.pdf
    • https://cdn.shopify.com/s/files/1/0433/8181/7495/files/19253909069.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000065bc.bin
799bcd96d50dcfa6037c295f72e5621396ba618d4cf0d19a4526d7fbf06d8b18
pdf-font-stream PDF embedded font (sfnt) at offset 0x65BC 5388 bytes
font_01_sfnt_off0000780f.bin
d11d9183bd7bfb1ed5c8f14a1376b238b6ab1bbfe9d701815b0b46d118fc216c
pdf-font-stream PDF embedded font (sfnt) at offset 0x780F 10504 bytes
font_02_sfnt_off00009bc2.bin
05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176
pdf-font-stream PDF embedded font (sfnt) at offset 0x9BC2 4324 bytes