Malicious PDF — malware analysis report

Static analysis result for SHA-256 64ab3074ccf85bb0…

MALICIOUS

PDF

63.2 KB Created: 2020-10-29 18:41:41 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-02
MD5: cf36e37c09db83f974583e60c26f4af4 SHA-1: d41c80edad50bf2f4ac1555edba7e63de5c8f86c SHA-256: 64ab3074ccf85bb037055ec4512894d486c7d42e8304243a9b33ea9b3197cd7b
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by an ML classifier. The file routes users through malicious redirector infrastructure. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/strik?keyword=dir+615+tomato In PDF document text
    • https://tenabawik.weebly.com/uploads/1/3/2/7/132710661/4e41c8e9a28c7b.pdfIn PDF document text
    • https://fexatawolev.weebly.com/uploads/1/3/4/4/134445796/jalawomonolamumabefu.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • http://www.daltonmaag.com/In PDF document text
    • https://cdn.shopify.com/s/files/1/0501/1845/9546/files/java_string_to_byte_array_fixed_length.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/63dc0d62-563a-41da-8198-919b9ad9d011/62586965199.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0481/6617/4871/files/the_developing_person_through_the_lifespan_chapter_5.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/55de0978-0e84-42f3-b03e-abb67ea081f4/tetuzatalulalezekumobu.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/b36ff47b-68aa-46cb-a905-02ae5402f6cf/ffxiv_blue_mage_spells.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/dce98261-eb92-445d-8276-2e741c313824/51203879678.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/f5d1e3c3-a542-4a3e-aabc-c336e3c26971/rupedidumusomoti.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bd4952a4-4e08-429d-8e78-e2853d6d6729/38960341740.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/e8a7bda8-f6fb-49f2-83b4-89425098e676/gopok.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0502/4422/3131/files/wesofuzanonogi.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0434/7556/6752/files/suzafijekixinebinokitop.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00008d49.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8D49 4516 bytes
SHA-256: 437d7e8eb9c48411a767eec0056fa705443fd574bf57bdacc8e417d1a90fc475
font_01_sfnt_off00009c9b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9C9B 14932 bytes
SHA-256: 395a933fa7f02727d5763ea72633cd8921ffa46dd81ced2259cdd4377d914e0a
font_02_sfnt_off0000ccb0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCCB0 16144 bytes
SHA-256: d2d14ee152591f1391b9c182731dc81228c2f3de4d706c9bd7d93c14ae925181
font_03_sfnt_off0000e1ad.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE1AD 4324 bytes
SHA-256: cd94ef65598b1866d0653cdd88243d989fd81359c0e770c2d3a4858f1c2f6d34