Malicious PDF — malware analysis report

Static analysis result for SHA-256 56faf0f4a3240158…

MALICIOUS

PDF

79.5 KB Created: 2021-03-16 02:41:33 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: e6afea562e3663abf70e0ea797b26993 SHA-1: dfc81e3d064fe7be401a147f9c186d2bd8d77b5a SHA-256: 56faf0f4a32401586da65e6cb06f45aced6e70774307b8cd0be484af1969121e
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link to a known malicious redirector, indicating a phishing or malware distribution attempt. The embedded content, though obfuscated, suggests a lure related to darts, likely to trick users into clicking the malicious link. The ML classifier and ClamAV detection strongly support the malicious nature of this file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/strik?utm_term=how+to+throw+180+in+darts
    • https://cdn-cms.f-static.net/uploads/4459937/normal_60275069715f7.pdf
    • https://cdn.sqhk.co/rozesivotix/iecTiam/how_to_make_crystal_mud_slime.pdf
    • https://static.s123-cdn-static.com/uploads/4471512/normal_5fe55d3f553e3.pdf
    • https://cdn.sqhk.co/tixuniwe/sDfuhbw/infinity_staffing_battle_creek_mi.pdf
    • https://static.s123-cdn-static.com/uploads/4365600/normal_5ffe632d53d80.pdf
    • https://cdn-cms.f-static.net/uploads/4366395/normal_602daf3db6624.pdf
    • https://cdn.sqhk.co/nokotadi/TQjdyyL/75915038686.pdf
    • https://cdn.sqhk.co/jagibuvat/piagfhg/towupujomumawufijox.pdf
    • https://cdn.sqhk.co/nozalodugavi/JehejcQ/kuwemobomo.pdf
    • https://cdn.sqhk.co/vemudumuxixu/hbiajiZ/denton_color_lab_reviews.pdf
    • https://cdn.sqhk.co/ferorigife/AGNEwjb/sokorakoxefogitokud.pdf
    • http://puvepum.getenjoyment.net/66611502897.pdf
    • https://cdn-cms.f-static.net/uploads/4374359/normal_6046ab300ef0d.pdf
    • http://wojesukuzak.mygamesonline.org/stihl_024_av_carburetor_adjustment.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://uploads.strikinglycdn.com/files/313bb1ae-9e71-40f4-bca1-11bbf963e597/a_tank_contains_125_gallons_of_heating_oil_at_time_t0.pdf
    • https://uploads.strikinglycdn.com/files/54fa0806-5f4e-445a-876c-16e0c0d3097c/new_game_show_with_the_chasers.pdf
    • https://uploads.strikinglycdn.com/files/1ccc584e-f3b9-4ce6-9557-c728a47bd500/fantastic_mr_fox_quotes_we_are_all_different.pdf
    • https://uploads.strikinglycdn.com/files/a804228e-6f8a-44ad-bafc-b57ba6a53e4d/chicago_times_sudoku.pdf
    • https://uploads.strikinglycdn.com/files/0ffcea6f-6708-4649-8f81-f66a30632b7b/sodikopavoz.pdf
    • http://fuxunowelujuxa.atwebpages.com/58419856526.pdf
    • https://uploads.strikinglycdn.com/files/f2cbc41f-f040-42d5-b32c-42a1cae7c07b/agatha_christies_poirot_season_13_episode_3_cast.pdf
    • https://uploads.strikinglycdn.com/files/d4452c12-5a2e-492e-a297-5826705b9ef1/dewalt_dwe7480_vs_dwe7491.pdf
    • http://zevesijuduma.atwebpages.com/zorba_the_greek_quotes_dance.pdf
    • https://uploads.strikinglycdn.com/files/f3e7220d-7d05-4ff6-80f9-69d5130205b5/hp_officejet_5510_driver_download_windows_7.pdf
    • https://uploads.strikinglycdn.com/files/3c0745cf-5616-48b6-8e0d-38f11b06ccf7/what_does_a_warm_and_fuzzy_mean.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000f8f2.bin
bd1d0c91483f91c8c72b15118a51421aade81ab8587969280a6ca19860e8c556
pdf-font-stream PDF embedded font (sfnt) at offset 0xF8F2 5320 bytes
font_01_sfnt_off00010b13.bin
9dfc1d79dbeaaa77b64e99f0bcbb1d66c4f53b184439b429b3b077142d7d4756
pdf-font-stream PDF embedded font (sfnt) at offset 0x10B13 11104 bytes