Malicious PDF — malware analysis report

Static analysis result for SHA-256 2dce13aa8d95fa30…

MALICIOUS

PDF

77.6 KB Created: 2020-12-24 07:45:12 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-11
MD5: f3dc84cd555117c1f0bcf7a597994975 SHA-1: bc57d712ea148906c76d581e88798ac7aff5ae70 SHA-256: 2dce13aa8d95fa303c7ebd5ccb0f3a1970ee4d5780d5cc958924bf9348e599a6
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://cctraff.ru/strik?utm_term=escape+game+50+rooms+2+level+24+erklarung'. This URL is likely used to redirect the user to a phishing or malware distribution site. The ML classifier also strongly indicated maliciousness, and ClamAV detected it as a phishing trojan.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/strik?utm_term=escape+game+50+rooms+2+level+24+erklarung In PDF document text
    • https://cdn.sqhk.co/wupifufexix/hbiawgh/ziteguzinawotifelunom.pdfIn PDF document text
    • https://cdn.sqhk.co/kupovite/hH3fjev/35679052223.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/0f281d85-b4df-4f30-bdef-9e75cceaca16/jelogabiwokumup.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/669b9ac9-af68-4194-8b3e-cb9eaec923e6/flying_mounts_pixelmon.pdfIn PDF document text
    • https://s3.amazonaws.com/sabegokek/dugakewuladepa.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/a53a990f-40c1-42a9-a6f6-5b2fe5078e8c/85429064444.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dd7b77f4-16bc-42ba-9533-23436794693e/ziweluja.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4aff293a-7942-411e-bcd5-19bb4f09a7ff/58649316981.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c01bc548-61ae-4b03-814f-2f70f4b4c2d4/insurgent_full_movie_free_online.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e6b1daf7-670f-47db-8e65-0e2300a9bc01/fullerton_ne_dmv_hours.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/6033fe79-a7f7-4b3f-8ff3-e971aa5ce507/mutonuvidedijaxufiberot.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/87a4619d-835a-4609-983f-0fda8771408c/suntrust_fraud_department.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/fbe1252f-f84f-4b99-9cc7-3c81832c9a6c/71253185187.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/c92f0a25-df91-4d76-8bce-c74cc6469f18/vitalina_wilson_fresno_ca.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/83ad714c-d2fa-43a0-bbf9-a6198827294a/59333569153.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f1f8.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF1F8 5820 bytes
SHA-256: 441302b6ab334f2a8bc173cf9ac4b8881722d62b40112c8d8cdb919ff9ec1978
font_01_sfnt_off000105d4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x105D4 10428 bytes
SHA-256: ebb704cc2bf6ad8070a36447d976a2f5645518e6e3ab9280c5507f4a64cc2bff