Malicious PDF — malware analysis report

Static analysis result for SHA-256 381bdc5902eb3ef3…

MALICIOUS

PDF

305.0 KB Created: 2020-10-03 17:02:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-05-22
MD5: 4239386e2193ed2e1f4b1e859958ae8f SHA-1: 16ab8202f40a571178c1589dedf8bc58b9146242 SHA-256: 381bdc5902eb3ef34b7f094deb5434072ce563670920b13f5ea89812a2702c72
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file was flagged by a machine learning classifier as malicious and contains a link to a known malicious redirector. The document body, though heavily obfuscated, also contains the same redirector URL. This suggests the primary purpose of the document is to redirect the user to a malicious website.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=micro+braid+twist+hair In PDF document text
    • https://site-1038919.mozfiles.com/files/1038919/maselubejetejotituz.pdfIn PDF document text
    • https://site-1037172.mozfiles.com/files/1037172/95749436608.pdfIn PDF document text
    • https://site-1036655.mozfiles.com/files/1036655/nekefekir.pdfIn PDF document text
    • https://site-1038924.mozfiles.com/files/1038924/vodulakifo.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://uploads.strikinglycdn.com/files/a56f76eb-2e69-40a8-860f-2df9f91766a4/gupiranibefepuf.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/446b954b-9e7e-47d8-9a5c-c32cc0d42add/guwasopabelatuwuka.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/459d7867-359a-4c4c-a21c-1354021ee037/vokebajerepo.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/ff6cce68-d5d5-495e-985e-23586ac0c1fd/fatoxiwiwefudaxanenor.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/7a29f1f8-699c-49f9-97df-8476b9dd8fab/91096911932.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0492/0115/2163/files/gupun.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0433/2175/3758/files/lds_holy_ghost_confirmation_blessing.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0487/0026/0502/files/calculating_average_atomic_mass_worksheet.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0480/2209/3983/files/maryland_tech_invitational.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/971b08de-5d07-4754-87c4-fafd34bf02c4/juzoga.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/def4236c-3f39-469e-b38e-2a1cc0109f44/keropitotafukelapezuwifem.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b3e67512-0e89-4d30-8644-fc34f743c8d7/pinubifitajeraxekotulolix.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000472ef.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x472EF 4796 bytes
SHA-256: 26bcb4642f6c56578f947cbdebd0b1ced3150d8ffcb2a156b4e5f00b9c3b1199
font_01_sfnt_off00048356.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x48356 10564 bytes
SHA-256: 9c4ad4c04d7af1fbf4a6a97019318cbb226b48054cdbb67bf0abe586749b6e1f
font_02_sfnt_off0004a784.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4A784 4324 bytes
SHA-256: 4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3