Malicious PDF — malware analysis report

Static analysis result for SHA-256 92654ccc91bc9ba7…

MALICIOUS

PDF

46.2 KB Created: 2020-11-02 04:28:46 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7) First seen: 2021-10-07
MD5: 99c00944477efe8c66a08aaae9afffc0 SHA-1: ce8338d76d8e65585e4d15d03a1392ac974d3261 SHA-256: 92654ccc91bc9ba735c540dbdf3dec92cc90b6efe1acf4dec086c872df42e91a
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a link to a known malicious redirector, indicating an attempt to lead the user to a malicious site. The ML classifier also strongly flagged this PDF as malicious. The document body, though heavily obfuscated, contains the same redirector URL, suggesting it is the primary lure.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.link/pify?keyword=german+unity+day+2019+date In PDF document text
    • https://cdn-cms.f-static.net/uploads/4384036/normal_5f965cc268013.pdfIn PDF document text
    • https://wetuxabo.weebly.com/uploads/1/3/0/8/130873937/3475387a65fc0.pdfIn PDF document text
    • https://vekejuritikoj.weebly.com/uploads/1/3/1/8/131857631/910391.pdfIn PDF document text
    • https://mojivimimujovo.weebly.com/uploads/1/3/0/8/130874437/sujikuw.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4393035/normal_5f9002a9dd416.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4403819/normal_5f97a4c0ce840.pdfIn PDF document text
    • https://cdn-cms.f-static.net/uploads/4365652/normal_5f8750ddd2e74.pdfIn PDF document text
    • https://nirotobilimob.weebly.com/uploads/1/3/4/4/134484477/tajujepusezetexex.pdfIn PDF document text
    • http://www.ascendercorp.com/In PDF document text
    • http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
    • https://s3.amazonaws.com/zuxadol/39411554429.pdfIn PDF document text
    • https://s3.amazonaws.com/gupuso/pengertian_amenore_sekunder.pdfIn PDF document text
    • https://s3.amazonaws.com/ragejufa/49750518002.pdfIn PDF document text
    • https://s3.amazonaws.com/xanebavifamopez/kobudozajiwet.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/46381c0d-1f62-4e5a-bd60-1897ead6cd98/geometry_b_midterm_review_packet_answers.pdfIn PDF document text
    • https://s3.amazonaws.com/jumedemimo/50596866325.pdfIn PDF document text
    • https://uploads.strikinglycdn.com/files/5e6864a9-da23-414f-a35d-baa36e4ea69b/41148318706.pdfIn PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://ns.adobe.com/pdf/1.3/In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://ns.adobe.com/xap/1.0/mm/In PDF document text
    • http://ns.adobe.com/xap/1.0/rights/In PDF document text
    • http://scripts.sil.org/OFLIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007549.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7549 5376 bytes
SHA-256: 380d448336d41c0d41525a7dd7d0a3938d695106b677a32877f3ff7b5388acd0
font_01_sfnt_off00008787.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8787 10836 bytes
SHA-256: 626ae4af9065b401242d20adec619ea72127f6d2df7062280d5935f4f1491677