Malicious PDF — malware analysis report

Static analysis result for SHA-256 39bceec2c67a4530…

MALICIOUS

PDF

71.3 KB Created: 2021-04-13 14:03:29 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-11-07
MD5: fed2af0ef6e7305e6b63bfe509310dd7 SHA-1: 1ef1ea5e961db3c4798061462c82e19a1f017440 SHA-256: 39bceec2c67a45309e381bdd36f213e03f267f7f66be0b3c2ec712a37c8d7011
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The sample is a PDF file flagged by multiple heuristics and a machine learning classifier as malicious. It contains an embedded URL that points to a known malicious redirector. The document body, though heavily obfuscated, contains metadata suggesting it was generated by wkhtmltopdf, a tool sometimes used to create malicious documents. The primary attack vector appears to be directing the user to a malicious external resource.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/strik?utm_term=the+theater+experience+13th+edition In PDF document text
    • https://cdn-cms.f-static.net/uploads/4371244/normal_6034ed0f13f81.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4526930/normal_5ff51f1b12ea1.pdfIn PDF document text
    • https://cdn.sqhk.co/fomanazoravu/jZDkpzo/glitter_live_wallpaper_apkpure.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4466391/normal_5feb7f94e9aa1.pdfIn PDF document text
    • https://cdn.sqhk.co/batijuretak/QdYhdjj/bonovoraze.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4494431/normal_602d2af1e57ba.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4475391/normal_6063ac8b313bd.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4485301/normal_5fd3a5a2bb42b.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4423154/normal_5fe16869cab25.pdfIn PDF document text
    • https://cdn.sqhk.co/xobetetivuzi/BGghgdS/segurawesesuser.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4451756/normal_6053a624bb7a0.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/c5d3155e-a46b-454c-9326-83d9c1669214/56670855021.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dfb1ad15-fea7-4a05-be5e-6d9ee9407915/likad.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/1f470337-cfa6-4940-8c21-9f36d868589c/rufoxad.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/33cfa292-746e-4ffc-8c32-603263e1ae5e/how_much_is_lexus_rx_350l.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/740e77fa-1fa1-490e-8e56-4a5d2dd9e841/84527630976.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8fcec314-d2a1-424d-9f65-559cd5025a84/the_wave_arizona_to_antelope_canyon.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/acbb3b39-87e1-4fc5-874d-446f8d2b8d62/wezetorurimew.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/03eb767c-72c5-471c-b33a-27af3d005603/2354176082.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/8f8039b0-9859-4f14-9149-2c1d748a2155/roland_tr8s_vs_elektron_digitakt.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/afc28c16-d2db-49d4-a10d-03e96b6e64a4/zimezaz.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/cc2998a5-33f8-450b-9490-cc12dc79b895/kolam.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000dbf0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xDBF0 5184 bytes
SHA-256: f4571149e51ce5d0393dc21b66ffc2543b688c211cd72737538fce111ae72fdb
font_01_sfnt_off0000ed96.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xED96 10088 bytes
SHA-256: 10bb7fdb593a32c5a89681c788a0be1b115717af4eaa6876a0c38240164bd19a