Malicious PDF — malware analysis report

Static analysis result for SHA-256 22d4ec754d5ab5f8…

MALICIOUS

PDF

68.7 KB Created: 2020-11-21 23:32:41 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-11
MD5: 9972fd2fce8a27a2b4027424f944cf0c SHA-1: 53b45219c7958a16051e5ac1d595076215f0fabd SHA-256: 22d4ec754d5ab5f83614c2f20dac483a3edac8da844fe9db2b5ef1c27e9aeb0c
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://traffine.ru/123?utm_term=what+is+the+text+structure'. This indicates the document's primary purpose is to lure the user to a potentially harmful external site. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted, but the presence of a malicious URL is sufficient evidence for a phishing or malware distribution attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffine.ru/123?utm_term=what+is+the+text+structure In PDF document text
    • https://dujenavu.weebly.com/uploads/1/3/4/3/134366251/309416b6fb2.pdfIn PDF document text
    • https://zovijewef.weebly.com/uploads/1/3/4/4/134400079/nowososijinikix_rulus.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4417033/normal_5fb81f5c6ed46.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4408598/normal_5fa0fcf06bd58.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4376404/normal_5f8c4b2bac88c.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4418575/normal_5fa866739d141.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4469355/normal_5fac13f4ea679.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4417327/normal_5fac2b45befbc.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4374178/normal_5fab7e933e5f7.pdfIn PDF document text
    • https://wusinetowaje.weebly.com/uploads/1/3/4/4/134471696/lovux.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/3f0159d0-dbd6-4562-a1c3-7532b2aa0970/calculus_early_transcendentals_1st_e.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b06c0113-118b-4e90-b8cf-04b66c947a5b/chapter_2_study_guide_using_si_units_answers.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/d43d14dd-c59c-4d4c-a434-86222bee0202/68605227761.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/77d22ddf-41da-48f7-a108-d18387aad1cf/7703040188.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/eb73b3b5-3210-4f8c-85d0-c2b03dfe34d5/63141569277.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d2cb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD2CB 4936 bytes
SHA-256: 3c0d2252eb6b5c9a745fae6a40e395219dc0baa75864890ddd2976e7bc287ad8
font_01_sfnt_off0000e39d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE39D 9916 bytes
SHA-256: 3566b3b018de340be48fbd38d2bd68be66b3a9662eef785262d735b32a67a357