Malicious PDF — malware analysis report

Static analysis result for SHA-256 2ff15c4e696847fd…

MALICIOUS

PDF

43.1 KB Created: 2020-11-06 02:40:14 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-27
MD5: e42398a93463253f0b28bbfc4830996c SHA-1: eb9738133d74962cfd731809b5a655b601f38527 SHA-256: 2ff15c4e696847fd770a10fe84b0d957e280c963482f438f7a61900faf376940
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged as malicious by an ML classifier and contains a link to known malicious redirector infrastructure. The embedded URL `https://traffine.ru/strik?keyword=mc+attunement+guide` is the primary indicator of malicious intent, likely serving as a lure for phishing or malware delivery. No scripts were extracted, but the presence of a malicious link strongly suggests a spearphishing attachment attack vector.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://traffine.ru/strik?keyword=mc+attunement+guide In PDF document text
    • https://cdn-cms.f-static.net/uploads/4407571/normal_5f937435e17b5.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4367922/normal_5f8a5a90f3eec.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4413122/normal_5fa4947951f1c.pdfIn PDF document text
    • https://nasotatuji.weebly.com/uploads/1/3/4/3/134392375/501d51a81367.pdfIn PDF document text
    • https://satobolusiv.weebly.com/uploads/1/3/1/3/131398412/f0e4143d9.pdfIn PDF document text
    • https://derodaju.weebly.com/uploads/1/3/1/6/131606282/f2aeea.pdfIn PDF document text
    • https://femitinekabel.weebly.com/uploads/1/3/1/4/131437683/dosebafizapixu_vemavovurabeba_bonuvajudavix.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/d1ed8f4c-aeb8-41a1-a45e-b85838c107f1/is_my_blood_type_listed_on_birth_certificate.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/eaed5a6d-87c9-4a14-a79c-75ae6fdf95bd/20394009463.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/4c44e8bd-9de9-450a-90f6-b09b0156b12c/43246914169.pdfIn PDF document text
    • https://s3.amazonaws.com/midipes/pomopiwa.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/25aea672-4ad4-4ff1-9506-d6cff80606c3/8924058952.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/0d728a05-1f46-40de-b94a-adde90d1f29a/rabutogafemot.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006cf6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6CF6 4956 bytes
SHA-256: 3ceea468df0eafa5fec5a698aadbec10b48e06e9b959a9596234c66e4cc6ed77
font_01_sfnt_off00007dd0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7DD0 10080 bytes
SHA-256: 79f8bbe7b2d67363eddd302b72bf230ec7e15b7b2d39d302b65998a6305412fb