Malicious PDF — malware analysis report

Static analysis result for SHA-256 902e8812bcab4678…

MALICIOUS

PDF

83.6 KB Created: 2020-12-25 20:53:44 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-04
MD5: 544af5d8f8e8b800d593dcb58b30ee03 SHA-1: 5b468fbdc8facd2ba6b1074f56204da334a6cf71 SHA-256: 902e8812bcab46780b2b4e06393bc142c6b74dab4e946078ec27963a936c0a63
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

This PDF document was flagged as malicious by ClamAV and an ML classifier. The file routes users through malicious redirector infrastructure. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ggtraff.ru/strik?utm_term=chikki+mod+apk+unlimited+coins+download In PDF document text
    • https://cdn-cms.f-static.net/uploads/4424933/normal_5fa9871e37c29.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4459630/normal_5fc408471614d.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4424630/normal_5f999fa7beb6b.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4412905/normal_5fa08af5487cf.pdfIn PDF document text
    • https://static.s123-cdn-static.com/uploads/4379229/normal_5fc7bfab15b5d.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://uploads.strikinglycdn.com/files/c1e1589a-13fa-4297-85f2-6de443f5a1a2/bufuvuwe.pdfIn PDF document text
    • https://s3.amazonaws.com/dixaleko/kaspersky_android_license.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/aa9d223c-8473-4f98-a285-987f04a10187/vimudoxid.pdfIn PDF document text
    • https://s3.amazonaws.com/tigewibejageju/heart_disease_caused_by_stress.pdfIn PDF document text
    • https://s3.amazonaws.com/xurixado/ahad_nama_arabic.pdfIn PDF document text
    • https://s3.amazonaws.com/levumoduf/dozenagirufosipej.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/3a2a22de-a787-4c3f-a32d-ae859136da33/planet_earth_caves_worksheet_answer_key.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/25171f6f-2475-4b10-ba70-db4ed934337f/outlander_2008_full_movie_in_tamil_dubbed.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • https://savannah.gnu.org/projects/freefont/In PDF document text
    • http://www.gnu.org/licenses/In PDF document text
    • http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
    • http://scripts.sil.org/OFLIn PDF document text
    • http://dejavu.sourceforge.netIn PDF document text
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text

Extracted artifacts 5

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000d35c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD35C 6408 bytes
SHA-256: b71bf7faf3a2ce2315c75c81a6c499eeb463499f5945c9b99d2f9af5b1770855
font_01_sfnt_off0000e328.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xE328 5276 bytes
SHA-256: 0563a611622edab69e7c7ef08fdc95b1c9501d52c4f77a3503a5ae63f161c9f2
font_02_sfnt_off0000f4f5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xF4F5 4624 bytes
SHA-256: 30aaca0e4c17ac00d56716ac3b641a64f111ac92d38ebe0ad079ce7691bde464
font_03_sfnt_off00010625.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x10625 10744 bytes
SHA-256: d2f391af757d10270f2c5a51ff42238b570b2c5273c0bd87354c1e03491dbeae
font_04_sfnt_off00012af9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x12AF9 16160 bytes
SHA-256: 7e63eb3bed9c4ceaf47e86587cf77a789dba98dd2b4db382f0c7f052a0aeb8ce