Malicious PDF — malware analysis report

Static analysis result for SHA-256 172dc6178a183cfa…

MALICIOUS

PDF

78.4 KB Created: 2021-01-08 09:20:03 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-27
MD5: 83bf6227a3bff75707a4ebd9ef5adf5c SHA-1: ea0d3de5d2ed62e1dc70d362d839c8aad0d77bdc SHA-256: 172dc6178a183cfaa43430873fc5e401eefc4de7d49ba34e6a318bf5465949c2
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link to a known malicious redirector, indicating a phishing or malware distribution attempt. The ML classifier and ClamAV detection strongly support this assessment. Although no scripts were explicitly extracted, the PDF structure and embedded URL suggest an attempt to redirect the user to a malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffine.ru/123?utm_term=bullseye+bbq+sauce+review In PDF document text
    • https://cdn-cms.f-static.net/uploads/4393761/normal_5fa52f5879be8.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/c1739b0f-2962-4e85-8213-fd6245f52099/free_amharic_orthodox_spiritual_books.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ba6827e0-1b56-4a27-a538-0fbe121649ce/french_alphabet_with_pronunciation.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6072b787-b703-49be-8aba-4ca3b604948d/legendary_game_of_heroes_cheats_ios.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1d8a55f9-2f96-4beb-af8a-430a84ee50a6/91462156626.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/07ad6b49-118d-46f3-8320-c0b576bd62be/23928157373.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8f8c616c-3f15-4625-8f2b-5411fea82f0c/kemojuduwewin.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a9e2df3b-8263-446e-ac03-4c0cba57b0c1/lijifobive.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/285da06c-ea99-400a-b38f-d523ca684468/zofibopiluzojikobo.pdfIn PDF document text
    • https://s3.amazonaws.com/rujabepifar/38384824753.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bc47db07-b4b6-40cb-84ca-b3bdc79eac3e/73423920461.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e860f678-1d32-4975-8d15-15d0ca60ee4a/nimoranudijaro.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/579b30ca-f2be-4b54-9c29-0674a2a3e6ea/xopifusosiler.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a368263e-ff7e-43c2-a5a9-511547969698/poptopia_caramel_popcorn_calories.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d5c9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD5C9 5364 bytes
SHA-256: 86349eb709d7f081dc4e3faec06c16a487a37e18067dee11338023699a83fbf0
font_01_sfnt_off0000e82c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE82C 1800 bytes
SHA-256: a36eee06fef6ce219692c4ec918276ac99413e4fd1e3666e4031624f9289d620
font_02_sfnt_off0000f0b9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF0B9 11304 bytes
SHA-256: 454567525c11487a113eda730964ab6635231e911e6f1ba4afc15416f619159b
font_03_sfnt_off00011748.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x11748 16092 bytes
SHA-256: 78e01a7a6136ddf0c994a311ff069c47b68cca607dacfa0833a94a83a26a5818