Malicious PDF — malware analysis report

Static analysis result for SHA-256 74ec6b1e652c85f0…

MALICIOUS

PDF

44.1 KB Created: 2020-11-02 03:50:52 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-04
MD5: 7326bc97b332efd9ac49a154b8dcea78 SHA-1: d5b112319f70bdb5e9764f1ea3cceb171feecad6 SHA-256: 74ec6b1e652c85f0eab74a13a256bff521893e48f1995e3126da7cebf4072fcc
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by an ML classifier. The file routes users through malicious redirector infrastructure. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/123?keyword=sss+sas+worksheet+pdf In PDF document text
    • https://cdn-cms.f-static.net/uploads/4370062/normal_5f892e10ad387.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4368245/normal_5f8a89d632df4.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4374956/normal_5f90dc72936f7.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4403407/normal_5f9110c431e19.pdfIn PDF document text
    • http://fontawesome.iohttp://fontawesome.io/license/In PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://cdn.shopify.com/s/files/1/0495/9053/4307/files/redemption_manual_45.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0495/2270/4550/files/82568375713.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0478/3203/9583/files/14001094407.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/bae481a7-35f3-4651-96cf-87d1a030a262/12297949904.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0482/6238/1729/files/96839953203.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0503/3318/8246/files/french_regular_verbs_conjugation_list.pdfIn PDF document text
    • https://s3.amazonaws.com/suximawo/aha_instructor_manual.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0496/2284/3545/files/waiting_for_godot_full_play.pdfIn PDF document text
    • https://cdn.shopify.com/s/files/1/0266/9445/1396/files/57207994917.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000513e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x513E 1776 bytes
SHA-256: e8af6d7b76feeda9a9fff8c5042e8f88e14e2db8b74c22857d584e3343e2b588
font_01_sfnt_off000059d0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x59D0 5356 bytes
SHA-256: 7d2c5211696f211ef266942159cc9f84789f190a9fe2e02637420e40bd18a14b
font_02_sfnt_off00006c1a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6C1A 9972 bytes
SHA-256: 08e396022de0a6c07317fb758a75add5333ae7c1392ed04aa04c5b1288bc7b83
font_03_sfnt_off00008e31.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8E31 16164 bytes
SHA-256: 1bda6b5102bdd0a2f2fb856b2a2a965bb8b97f6a9bddc68167f75b397cba9900