Malicious PDF — malware analysis report

Static analysis result for SHA-256 977d7658c39481b5…

MALICIOUS

PDF

42.6 KB Created: 2020-11-02 04:57:47 +02:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c1cbe500f9909fccbecb0c98f9c32ae5 SHA-1: e539f7a206c22a401a7143f1015559a5b87be5b1 SHA-256: 977d7658c39481b58f1948859ba147dd28debd5c8e4f57f9bada1ab8134e129b
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a link to a known malicious redirector, https://cctraff.ru/aws?keyword=minecraft+guide+to+survival+book, which is likely intended to lead the user to a phishing or malware download site. The ML classifier also strongly indicated maliciousness. No scripts were extracted, but the embedded URL is sufficient evidence of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://cctraff.ru/aws?keyword=minecraft+guide+to+survival+book
    • https://cdn-cms.f-static.net/uploads/4384144/normal_5f8fbd11e82d0.pdf
    • https://cdn-cms.f-static.net/uploads/4368469/normal_5f90cfd5c7bae.pdf
    • https://cdn-cms.f-static.net/uploads/4374710/normal_5f9000bc05a72.pdf
    • https://savakorudefipe.weebly.com/uploads/1/3/2/3/132303238/3854489.pdf
    • https://cdn-cms.f-static.net/uploads/4377113/normal_5f8a143e7a1eb.pdf
    • https://cdn-cms.f-static.net/uploads/4367299/normal_5f99b78ee368b.pdf
    • https://cdn-cms.f-static.net/uploads/4393220/normal_5f8f8c367dd0d.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://www.daltonmaag.com/
    • https://uploads.strikinglycdn.com/files/5a2b635e-c179-435c-b42d-8ae6a36c3a35/jiper.pdf
    • https://uploads.strikinglycdn.com/files/6dd00f1e-1d15-4488-a17a-cb6cdd308a04/burke_williams_gift_card_promotion.pdf
    • https://s3.amazonaws.com/subud/ancient_india_history_notes.pdf
    • https://uploads.strikinglycdn.com/files/150e0180-55b7-453b-b456-886af690def7/shinestar_sata_4_port_card_drivers_download.pdf
    • https://uploads.strikinglycdn.com/files/5dff559f-9990-4657-a279-500acc9e9b7d/star_ocean_first_departure_private_action_guide.pdf
    • https://s3.amazonaws.com/fasanag/exercices_sur_les_bascules.pdf
    • https://s3.amazonaws.com/xanebavifamopez/15908563418.pdf
    • https://s3.amazonaws.com/fifomi/wadetufos.pdf
    • https://s3.amazonaws.com/pazifetanegapu/8823881364.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000055e5.bin
fd3e297e416004b12056795e3eff3236f56befa59c8113893277ec500b0fa2d3
pdf-font-stream PDF embedded font (sfnt) at offset 0x55E5 5340 bytes
font_01_sfnt_off0000681d.bin
f2143aa9b2555a7458f2addc3ee06f1f1efb491f6f8117c63b917ffed2ab50a7
pdf-font-stream PDF embedded font (sfnt) at offset 0x681D 11344 bytes
font_02_sfnt_off00008d7c.bin
05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176
pdf-font-stream PDF embedded font (sfnt) at offset 0x8D7C 4324 bytes