Malicious PDF — malware analysis report

Static analysis result for SHA-256 74f41e701342aa93…

MALICIOUS

PDF

70.7 KB Created: 2021-04-01 01:26:26 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 4728793250210317adbdcc5cf6beebe5 SHA-1: 7e76c312d1639a2ca60c2dacbc9226a0a36e343b SHA-256: 74f41e701342aa93510fa1697784132c242d2e67298c0b525d3a81fa631384d9
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://yafferge.ru/wix?keyword=separating+mixtures+virtual+lab+answer+key'. This URL is presented within the document's content, suggesting a phishing or redirection attempt. The ML classifier also strongly flagged this PDF as malicious, supporting the conclusion that the document is designed to lead users to harmful infrastructure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9996

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/wix?keyword=separating+mixtures+virtual+lab+answer+key
    • http://zavudonalu.66ghz.com/installment_sales_contract_on_credit_report.pdf
    • http://wifefavowe.iblogger.org/24155930529.pdf
    • http://mamikuv.iblogger.org/molebogakogopunatolelew.pdf
    • http://krokoboko3.xyz/vusikise9h6wt.pdf
    • http://shoop-fl.ru/viwufelumugikafujer3xm5.pdf
    • http://pusikoxelumide.iblogger.org/an_astrologer_s_day_by_r._k._narayan.pdf
    • http://zivudib.66ghz.com/android_booster_notification.pdf
    • http://cheapestshop.xyz/facebook_videos_online_google_chromeprbji.pdf
    • http://rojemop.iblogger.org/53263006069.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://mowowaruxuxizim.rf.gd/quickbooks_aging_report_incorrect.pdf
    • https://uploads.strikinglycdn.com/files/57a25e9e-387d-4d1a-a16e-64fe9f78dc94/toshiba_regza_42_inch_review.pdf
    • http://xonowazibekaz.epizy.com/json_formatter_plugin_chrome.pdf
    • http://kilubediboxut.rf.gd/dekejusatiwimupiraref.pdf
    • https://uploads.strikinglycdn.com/files/767ce3d9-f156-4758-9c92-6bf9c7ffab73/como_agua_para_chocolate_libro_completo_descargar.pdf
    • http://daxajokawutuv.rf.gd/89129332329.pdf
    • http://womogesupepup.epizy.com/tactical_pistol_drills.pdf
    • http://pevuzimoba.rf.gd/61142893437.pdf
    • https://uploads.strikinglycdn.com/files/61be9722-0702-45d8-a30a-736b2083aa8b/what_are_the_characteristics_of_greek_art.pdf
    • https://uploads.strikinglycdn.com/files/05c6a09d-efc8-408a-8a3e-cae42ac19b97/how_to_operate_ge_front_load_washer.pdf
    • http://vufosal.rf.gd/rational_numbers_operations_worksheet.pdf
    • https://uploads.strikinglycdn.com/files/d3962106-9526-429f-8238-6ec176885a0d/how_to_get_grand_theft_auto_on_ps4.pdf
    • http://janibiledepe.rf.gd/keguparamalar.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d60e.bin
40430793ff804f472127212388868adcf4c857b07cf8f1a98718157bf17ac713
pdf-font-stream PDF embedded font (sfnt) at offset 0xD60E 5768 bytes
font_01_sfnt_off0000e9bb.bin
4eb9af6d2541896f804558ae2030d31a2fc013e89c9245182a30aa1b83eda7dc
pdf-font-stream PDF embedded font (sfnt) at offset 0xE9BB 10376 bytes