Malicious PDF — malware analysis report

Static analysis result for SHA-256 89d47ea872cb15f6…

MALICIOUS

PDF

55.2 KB Created: 2020-08-15 16:38:25 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-09-15
MD5: dc97726e5a929d8d21ad7e48b64f9a57 SHA-1: 2936702e2ac43a520a2d42a2964eddb79593be53 SHA-256: 89d47ea872cb15f6d6ea4b35f3fdfddc65cd635d35cd78b75da7cc90cd90bf20
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link farm and a redirector URL, indicating an attempt to lead users to malicious content. The embedded URL and the document body text suggest a lure related to educational materials. The ML classifier strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9982

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PDFSyntaxError. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=factoring+polynomials+review+pdf In PDF document text
    • http://files.randolphmusic.org/uploads/1/3/1/6/131607131/9494943.pdfIn PDF document text
    • http://files.thesolidrockshop.com/uploads/1/3/0/8/130813797/zaxisufibuxuxigusi.pdfIn PDF document text
    • http://files.projectbazia.org/uploads/1/3/1/6/131637679/nomurapasemixal.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://cdn.shopify.com/s/files/1/0430/1645/4305/files/67004353029.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0440/7197/7110/files/1404088476.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0430/2965/9797/files/69278686292.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0433/2965/0843/files/88628589693.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0429/5216/3482/files/zimox.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0428/1312/8867/files/53984624313.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0433/9574/3907/files/jubirelajiwejogenemuje.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0429/6792/4899/files/steuerklasse_wechseln_nrw.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0434/7068/4317/files/14577004308.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0434/1887/8117/files/79624118337.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0431/5319/5165/files/tobepibaleginikumuvikili.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0430/3945/7431/files/apc_ups_750_manual.pdfIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008b0f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8B0F 5472 bytes
SHA-256: 05e775e5cb50c4415cff16a7d4035c9759be5e5c8d151890e9348cd386615751
font_01_sfnt_off00009dab.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9DAB 14392 bytes
SHA-256: 8514d5a6182e63bd3e44b6f95082a9062aaec688d97bd9db10746f4791ee601f
font_02_sfnt_off0000cacb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCACB 4324 bytes
SHA-256: b50a2106bf82917db0cd3cf88f63c5e8cc3298b343ace5cffc591b35df33d24c