Malicious PDF — malware analysis report

Static analysis result for SHA-256 870315082998c245…

MALICIOUS

PDF

48.0 KB Created: 2020-07-30 23:13:07 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: f4fc0455c3db5a9f0e07ad38d73f529d SHA-1: 298e56532db3bb41a492bd4ddc8a330ba666fa17 SHA-256: 870315082998c24571ffa0999fdbc8f9768617ad896d5bfe5031278ebb14f487
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links, many of which point to a redirector service known to host malicious content. The document body, though heavily obfuscated, appears to be a lure related to 'research capstone project pdf'. The ML classifier strongly indicates maliciousness, and the presence of numerous external links suggests an attempt to drive traffic to potentially harmful sites.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=research+capstone+project+pdf
    • http://files.benjamincarkeyreplacement.com/uploads/1/3/1/3/131398143/fupirafadexer-rujidu-jotosi-xawabepagip.pdf
    • http://files.lacrescentareaeventcenter.org/uploads/1/3/0/9/130970004/6485625.pdf
    • http://files.fullcirclewnc.org/uploads/1/3/2/8/132816036/busabawugud.pdf
    • http://files.castlesjewelry-gifts.com/uploads/1/3/0/8/130813399/karilu_fojejodijatozix.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0429/1559/4393/files/42197199352.pdf
    • https://cdn.shopify.com/s/files/1/0435/1718/2104/files/69053227219.pdf
    • https://cdn.shopify.com/s/files/1/0437/4292/0869/files/dewenuwubobedilatarug.pdf
    • https://cdn.shopify.com/s/files/1/0435/2868/3672/files/risapagikatufibema.pdf
    • https://cdn.shopify.com/s/files/1/0429/5960/1830/files/jexasa.pdf
    • https://cdn.shopify.com/s/files/1/0428/9023/1974/files/letaxefarilufalupak.pdf
    • https://cdn.shopify.com/s/files/1/0435/2396/5079/files/rakuvipibefirutir.pdf
    • https://cdn.shopify.com/s/files/1/0434/0498/4483/files/6284278348.pdf
    • https://cdn.shopify.com/s/files/1/0432/9802/9733/files/89618863332.pdf
    • https://cdn.shopify.com/s/files/1/0429/2175/4787/files/283821937.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007f1f.bin
799f3680a1a68da04c77e3e60ae14d9dca8966a3a3e810c5a6b495e5e4577358
pdf-font-stream PDF embedded font (sfnt) at offset 0x7F1F 5036 bytes
font_01_sfnt_off0000903a.bin
07f2f7133123ca20fb06ebaa625d4e1500ae67f52f767bdc0e2bb4f7dcbfcc1b
pdf-font-stream PDF embedded font (sfnt) at offset 0x903A 10252 bytes