Malicious PDF — malware analysis report

Static analysis result for SHA-256 805e6a64600505fd…

MALICIOUS

PDF

69.4 KB Created: 2021-02-20 04:11:02 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: 5d614d5968671d35ea116a7bc0b0a561 SHA-1: 5df2e9c23949293bd675b7d825ce30839286f5ef SHA-256: 805e6a64600505fd5b0686e5cae419f4bb1c92d0a87f2f5995d3f70077b0474f
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a critical heuristic firing indicating it links to known malicious redirector infrastructure, specifically 'https://yafferge.ru/strik?utm_term=animal+farm+chapter+10+questions+and+answers'. This suggests the document's primary purpose is to lure the user to this malicious URL, likely for phishing or to download further malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://yafferge.ru/strik?utm_term=animal+farm+chapter+10+questions+and+answers
    • https://cdn.sqhk.co/xijogedobu/dHPiiMW/minecraft_tower_defence_unblocked_hacked.pdf
    • https://static.s123-cdn-static.com/uploads/4423732/normal_5fec954a29b11.pdf
    • https://static.s123-cdn-static.com/uploads/4374686/normal_6000531f85161.pdf
    • https://static.s123-cdn-static.com/uploads/4376602/normal_5ff38d1c385cc.pdf
    • https://cdn.sqhk.co/jaguwubax/shfjdA3/82301218472.pdf
    • https://static.s123-cdn-static.com/uploads/4365639/normal_60021d6ee4473.pdf
    • https://cdn-cms.f-static.net/uploads/4375699/normal_601840e2428a7.pdf
    • https://cdn.sqhk.co/birugafomafo/giidFja/9557872640.pdf
    • https://static.s123-cdn-static.com/uploads/4464539/normal_5fe3400cde586.pdf
    • https://static.s123-cdn-static.com/uploads/4377717/normal_5fdd324bdd349.pdf
    • https://cdn.sqhk.co/volinafi/cUjjo74/61391585742.pdf
    • https://cdn.sqhk.co/kalijada/Jr99iee/mixeposem.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://s3.amazonaws.com/gateme/natovefukowe.pdf
    • https://s3.amazonaws.com/purufiz/domino_theory_of_accident_causation_wikipedia.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d241.bin
6e2a1ab6860244533b719563812800e7ca15141897d4e39e0c66a71a440b04de
pdf-font-stream PDF embedded font (sfnt) at offset 0xD241 5796 bytes
font_01_sfnt_off0000e5e1.bin
5c9c57004d57ee31e3ff049d345b65b9debf4ae472719bfde45e5398bf9d3ce3
pdf-font-stream PDF embedded font (sfnt) at offset 0xE5E1 10236 bytes