Malicious PDF — malware analysis report

Static analysis result for SHA-256 44d614929aece930…

MALICIOUS

PDF

116.3 KB Created: 2021-05-19 07:47:16 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: bf5a701988d4b0918c1f1b561b9ebae8 SHA-1: 034f9ab753377f18c3bd10535e70c6dbe8a600c5 SHA-256: 44d614929aece930163d3c85ebb0af1b83ea7eda73baf53425df1af74ce511b0
122 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF file contains a link to a known malicious redirector, indicating an attempt to phish or deliver malware. The ClamAV detection further supports its malicious nature. Although no scripts were explicitly extracted, the PDF structure and embedded link suggest it's designed to trick users into visiting a harmful site.

Machine Learning

  • Nyx PDF Classifier clean score 0.1369

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/strik?utm_term=what+are+the+basic+categories+of+electrical+symbols
    • http://nusururak.22web.org/52220571220.pdf
    • https://static.s123-cdn-static.com/uploads/4408599/normal_5fdfaadcce464.pdf
    • https://static.s123-cdn-static.com/uploads/4379612/normal_5fe2a06993661.pdf
    • https://cdn-cms.f-static.net/uploads/4427781/normal_5fdbacd0ad4ed.pdf
    • http://rofodas.22web.org/5920711061.pdf
    • https://static.s123-cdn-static.com/uploads/4375699/normal_5fc94368aa149.pdf
    • https://cdn-cms.f-static.net/uploads/4426415/normal_604cd5a1919b9.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fedorahosted.org/lohit
    • http://smc.org.in)MeeraRegularMeera2016SMC7.0.0+20171102Hussain
    • http://smc.org.inhttp://smc.org.in
    • https://s3.amazonaws.com/pasutiz/xoxilasawuxamu.pdf
    • https://s3.amazonaws.com/liwafo/ugly_duckling_story_book.pdf
    • https://uploads.strikinglycdn.com/files/fcb74b31-bcb5-4d85-9ba2-fe6f598aeec9/can_you_use_native_instruments_maschine_without_hardware.pdf
    • https://uploads.strikinglycdn.com/files/d0372fd0-3b5f-48b8-9d6a-d20f2b355841/what_are_the_2_types_of_inferential_statistics.pdf
    • https://s3.amazonaws.com/takebemanijewok/nexamudoridefavegepa.pdf
    • https://uploads.strikinglycdn.com/files/ca4979bb-c443-4e60-9e2e-c34d4c919d97/2021_ford_mustang_mach-e_california_route_1_specs.pdf
    • https://s3.amazonaws.com/dudurat/best_calorie_counter_app_uk_2020.pdf
    • https://uploads.strikinglycdn.com/files/c2e731ba-5f44-4c01-8a36-a9dc941809c1/dikotexatabu.pdf
    • http://dinilemave.epizy.com/physical_appearance_vocabulary_worksheet.pdf
    • https://uploads.strikinglycdn.com/files/0c6d3ac2-981a-4a42-a13b-6ec898fbe419/the_crucible_a_man_will_not_cast_away_his_good_name.pdf
    • https://uploads.strikinglycdn.com/files/a9b5fab9-c5b7-411c-906c-9ada773ed5d9/how_to_put_bobbin_in_brother_ls-1217.pdf
    • https://uploads.strikinglycdn.com/files/2aa83077-c68a-4513-a4b2-166530e9d932/2019_ram_1500_big_horn_crew_cab_4x4_towing_capacity.pdf
    • http://bedisil.epizy.com/arbeitsvertrag_schweiz.pdf
    • https://s3.amazonaws.com/mupukesunobaga/bugaboo_frog_britax_car_seat_adapter.pdf
    • https://uploads.strikinglycdn.com/files/dddd7299-e882-4940-bc94-17eeab512e4b/who_is_little_mermaids_dad.pdf
    • http://xukorigukem.rf.gd/how_to_help_my_dogs_joints.pdf
    • http://scripts.sil.org/OFL
    • http://www.geocities.com/mitra_anirban/hobbies.htmGNU
    • http://www.gnu.org/copyleft/gpl.htmRegular
    • https://gitlab.com/smc/meera/blob/master/COPYING
    • http://sinhala.sourceforge.net/
    • http://sinhala.cvs.sourceforge.net/viewvc/*checkout*/sinhala/sinhala/fonts/CREDITS
    • http://www.gnu.org/licenses/gpl-2.0.html
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 9

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f531.bin
b7ef52d8e757836482904c1ac40d3e1d566e0fae24b51fa3acfda354ba3dd6b0
pdf-font-stream PDF embedded font (sfnt) at offset 0xF531 11432 bytes
font_01_sfnt_off00011a7f.bin
cc54853dafdafb47eea2a9e6eeff29dd57cffe5c14d8661c6b528cfbddb7855d
pdf-font-stream PDF embedded font (sfnt) at offset 0x11A7F 5548 bytes
font_02_sfnt_off00012d4d.bin
45be78afdcd29d6fc83fcb6af7c35510be5c8683000902661dc178f4541739c6
pdf-font-stream PDF embedded font (sfnt) at offset 0x12D4D 4736 bytes
font_03_sfnt_off00013e02.bin
1413711d874dea50ca8936853d4746e3ed33f252b3437f297d151eaf3307386c
pdf-font-stream PDF embedded font (sfnt) at offset 0x13E02 5496 bytes
font_04_sfnt_off00015001.bin
72a1a78c5849801bb82a1dd530f7222d9bc9bdb81c63fd7ea9d923c691e96b96
pdf-font-stream PDF embedded font (sfnt) at offset 0x15001 5704 bytes
font_05_sfnt_off0001633f.bin
de0cf8abd3194020de016793bb411be2b840d6d0b17ef37cb3f9b0db18584bb6
pdf-font-stream PDF embedded font (sfnt) at offset 0x1633F 7716 bytes
font_06_sfnt_off00017b57.bin
d209c9d7656e2dfb578bbdc8dabf96d41b7f989ffa0a142a49c626501ea8cbd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x17B57 3100 bytes
font_07_sfnt_off00018823.bin
7f3030161ce88314e53e7cfd23ccf431506d016025cb0328dd53db0f350a4af6
pdf-font-stream PDF embedded font (sfnt) at offset 0x18823 12376 bytes
font_08_sfnt_off0001aefd.bin
d44c1b849da8099ff1e07490b6eefdfe57c3d2a5d792e866f29f604c32b22ee7
pdf-font-stream PDF embedded font (sfnt) at offset 0x1AEFD 19144 bytes